vendor:
Stripe Payments
by:
Park Won Seok
7.5
CVSS
HIGH
Stored Cross-site scripting (XSS)
79
CWE
Product Name: Stripe Payments
Affected Version From: 2.0.39
Affected Version To: 2.0.39
Patch Exists: YES
Related CWE: N/A
CPE: a:wordpress:stripe_payments
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows 10 x64
2021
WordPress Plugin Stripe Payments 2.0.39 – ‘AcceptStripePayments-settings[currency_code]’ Stored XSS
A Stored Cross-site scripting (XSS) was discovered in wordpress plugins stripe-payments (Ver_2.0.39). Vulnerability parameters : 'AcceptStripePayments-settings[currency_code]' have Cross-Site Scripting.
Mitigation:
Input validation and output encoding should be used to prevent XSS attacks.