The Stripe Payment Forms by WP Full Pay WordPress plugin before 8.5.1 does not properly verify that a customer portal session has completed its confirmation step before returning data, allowing unauthenticated users to read another customer's subscription and billing information.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-08-26 06:16
Updated : 2026-08-26 16:30
NVD link : CVE-2026-77758
Mitre link : CVE-2026-77758
CVE.ORG link : CVE-2026-77758
JSON object : View
Products Affected
No product.
CWE
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor
