CVE · Medium

CVE-2023-48285 — Accept Stripe Payments [stripe-payments] < 2.0.80

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2023-48285 Accept Stripe Payments [stripe-payments] < 2.0.80 Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) Medium 5.3 < 2.0.80 2.0.80 2023-11-23

CVE-2023-48285

The Accept Stripe Payments plugin for WordPress contained a content injection flaw that could be exploited by attackers to insert malicious content into website pages and posts. This vulnerability could be leveraged to distribute phishing pages or other harmful content through compromised sites. The issue was discovered by Joshua Chan and remedied starting with version 2.0.80, making it essential for users running earlier versions to upgrade immediately.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.