Vulnerabilidades conocidas, compatibilidad con PHP y alternativas más seguras para el plugin de WordPress Stripe Payments — verificado contra la base de datos de seguridad local de WP Clinic.
Qué hace este plugin
- Slug:
stripe-payments
- 20000+ instalaciones activas
paymentpaymentsstripestripe gatewaystripe payments
Estado de mantenimiento
- Última versión conocida: 2.1.0
- Requiere PHP: 7.4+
- PHP máximo soportado (analizado): <8.0
Vulnerabilidades conocidas
6 CVEs conocidos registrados para Stripe Payments.
Reportadas entre 2021 y 2026.
| CVE |
Vulnerabilidad |
Tipo |
Gravedad |
Afectadas |
Corregido en |
Publicado |
Estado |
|
CVE-2021-47983
|
Accept Stripe Payments [stripe-payments] <= 2.0.39 (unfixed) |
— |
Media
6,4
|
< 2.0.39
|
2.0.39 |
2026-06-08 |
✓ corregido en la última versión
|
|
CVE-2026-42752
|
Accept Stripe Payments [stripe-payments] < 2.0.99 |
Violación del comportamiento esperado |
Media
6,5
|
< 2.0.99
|
2.0.99 |
2026-05-29 |
✓ corregido en la última versión
|
|
CVE-2024-7353
|
Accept Stripe Payments [stripe-payments] < 2.0.87 |
Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) |
Media
5,4
|
< 2.0.87
|
2.0.87 |
2024-08-06 |
✓ corregido en la última versión
|
|
CVE-2023-48285
|
Accept Stripe Payments [stripe-payments] < 2.0.80 |
Neutralización incorrecta de etiquetas HTML relacionadas con scripts en una página web (XSS básico) |
Media
5,3
|
< 2.0.80
|
2.0.80 |
2023-11-23 |
✓ corregido en la última versión
|
|
CVE-2023-48286
|
Accept Stripe Payments [stripe-payments] < 2.0.80 |
Falta de control de autorización |
Alta
8,2
|
< 2.0.80
|
2.0.80 |
2023-11-23 |
✓ corregido en la última versión
|
|
CVE-2022-2194
|
Accept Stripe Payments [stripe-payments] < 2.0.64 |
Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) |
Media
4,8
|
< 2.0.64
|
2.0.64 |
2022-06-27 |
✓ corregido en la última versión
|
|
—
|
Accept Stripe Payments [stripe-payments] < 2.0.54 |
— |
Desconocido
|
< 2.0.54
|
2.0.54 |
2022-03-14 |
✓ corregido en la última versión
|
|
—
|
Accept Stripe Payments [stripe-payments] < 2.0.40 |
— |
Desconocido
|
< 2.0.40
|
2.0.40 |
2021-01-08 |
✓ corregido en la última versión
|
CVE-2021-47983
WordPress Plugin Stripe Payments 2.0.39 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts through the AcceptStripePayments-settings[currency_code] parameter. Attackers can submit POST requests to /wp-admin/options.php with script payloads in the currency_code field to execute arbitrary JavaScript in administrator browsers when settings are viewed.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
CVE.org
CVE-2026-42752
<p>WordPress Stripe Payments Plugin <= 2.0.98 is vulnerable to Bypass Vulnerability</p><p>Software: Stripe Payments</p><p>Fixed in version 2.0.99 </p><p>Affected Version <= 2.0.98</p><p>CVE: CVE-2026-42752</p>
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Patchstack
CVE-2024-7353
The Accept Stripe Payments plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's accept_stripe_payment_ng shortcode in all versions up to, and including, 2.0.86 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
CVE.org
CVE-2023-48285
Update the WordPress Stripe Payments plugin to the latest available version (at least 2.0.80).
Joshua Chan discovered and reported this Content Injection vulnerability in WordPress Stripe Payments Plugin. This could allow a malicious actor to inject their own content into pages and posts of your website. This could also be abused to inject phishing pages into your website. This vulnerability has been fixed in version 2.0.80.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Patchstack
CVE-2023-48286
Update the WordPress Stripe Payments plugin to the latest available version (at least 2.0.80).
Joshua Chan discovered and reported this Broken Access Control vulnerability in WordPress Stripe Payments Plugin. A broken access control issue refers to a missing authorization, authentication or nonce token check in a function that could lead to an unprivileged user to executing a certain higher privileged action. This vulnerability has been fixed in version 2.0.80.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Patchstack
CVE-2022-2194
The Accept Stripe Payments WordPress plugin before 2.0.64 does not sanitize and escape some of its settings, allowing high privilege users such as admin to perform cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
CVE.org
Accept Stripe Payments [stripe-payments] < 2.0.54
Cross-Site Request Forgery (CSRF) vulnerability discovered in WordPress Accept Stripe Payments plugin (versions <= 2.0.53).
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Patchstack
Accept Stripe Payments [stripe-payments] < 2.0.40
Authenticated Stored Cross-Site Scripting (XSS) vulnerability found by Park Won Seok in WordPress Stripe Payments plugin (versions <= 2.0.39).
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Patchstack
+ 2 vulnerabilidades conocidas más
| CVE |
Vulnerabilidad |
Tipo |
Gravedad |
Afectadas |
Corregido en |
Publicado |
Estado |
|
—
|
Accept Stripe Payments [stripe-payments] < 2.0.40 |
— |
Desconocido
|
< 2.0.40
|
2.0.40 |
2021-01-05 |
✓ corregido en la última versión
|
|
—
|
Accept Stripe Payments [stripe-payments] < 2.0.40 |
— |
Desconocido
|
< 2.0.40
|
2.0.40 |
— |
✓ corregido en la última versión
|
Accept Stripe Payments [stripe-payments] < 2.0.40
The Accept Stripe Payments plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘currency_code’ parameter in versions up to, and including, 2.0.39 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
Accept Stripe Payments [stripe-payments] < 2.0.40
The Stripe Payments WordPress plugin, version 2.0.39 and possibly below, was vulnerable to Stored Cross-Site Scripting (XSS) in the plugin's currency_code settings parameter.
The form did require a valid CSRF nonce, limiting the exploitability of the vulnerability.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
WPScan
Cómo solucionarlo
Mantén Stripe Payments actualizado — 2.1.0 es la última versión en wordpress.org, y cada CVE de arriba indica la versión exacta que lo corrigió ("Corregido en").
Este es el historial completo de vulnerabilidades conocidas del plugin, no un escaneo de una instalación específica — ejecuta un escaneo gratis de tu propio sitio para verificar tu versión instalada exacta.
Alternativas más seguras / más establecidas