CVE · Medium

CVE-2022-2194 — Accept Stripe Payments [stripe-payments] < 2.0.64

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2022-2194 Accept Stripe Payments [stripe-payments] < 2.0.64 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 4.8 < 2.0.64 2.0.64 2022-06-27

CVE-2022-2194

The Accept Stripe Payments plugin prior to version 2.0.64 fails to properly sanitize and escape certain configuration options, creating a cross-site scripting vulnerability that high-privileged users like administrators can exploit even when the unfiltered_html capability has been restricted.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.