The Stripe Payment Forms by WP Full Pay WordPress plugin before 8.5.1 does not verify that a subscription belongs to the customer bound to the requesting customer-portal session before acting on it, allowing a user with a confirmed portal session to cancel, reactivate or modify subscriptions belonging to other customers.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-08-26 06:16
Updated : 2026-08-26 16:30
NVD link : CVE-2026-77789
Mitre link : CVE-2026-77789
CVE.ORG link : CVE-2026-77789
JSON object : View
Products Affected
No product.
CWE
CWE-639
Authorization Bypass Through User-Controlled Key
