CVE · High

CVE-2023-48286 — Accept Stripe Payments [stripe-payments] < 2.0.80

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2023-48286 Accept Stripe Payments [stripe-payments] < 2.0.80 Missing Authorization High 8.2 < 2.0.80 2.0.80 2023-11-23

CVE-2023-48286

The Accept Stripe Payments plugin for WordPress contained a broken access control vulnerability prior to version 2.0.80 that allowed unauthorized users to perform actions normally restricted to privileged accounts. The flaw stemmed from insufficient authorization checks, missing authentication mechanisms, or absent nonce token validation in certain plugin functions. Joshua Chan identified and disclosed this issue, which has been remedied in version 2.0.80 and later releases.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.