PLUGIN SECURITY
Is Stripe Payments safe?
Easily accept payments on your WordPress site via Stripe payment gateway.
What this plugin does
- Slug:
stripe-payments - Author: mra13 / Team Tips and Tricks HQ
- 20000+ active installs
- 82/100 rating (114 reviews on wordpress.org)
- 2079112 all-time downloads
- On WordPress.org since 2015-03-03
paymentpaymentsstripestripe gatewaystripe payments
Maintenance status
- Latest known version: 2.1.1
- Last updated: 2026-08-21 3:48am GMT
- Tested up to WordPress: 7.1
- Requires PHP: 7.4+
- Max supported PHP (analyzed): <8.0
Known vulnerabilities
6 known CVEs on file for Stripe Payments. Reported between 2021 and 2026.
| CVE | Vulnerability | Type | Severity | Affected | Fixed in | Published | Status |
|---|---|---|---|---|---|---|---|
| CVE-2021-47983 | Accept Stripe Payments [stripe-payments] <= 2.0.39 (unfixed) | — | Medium 6.4 | < 2.0.39 | 2.0.39 | 2026-06-07 | ✓ fixed in latest |
| CVE-2026-42752 | Accept Stripe Payments [stripe-payments] < 2.0.99 | Expected Behavior Violation | Medium 6.5 | < 2.0.99 | 2.0.99 | 2026-05-29 | ✓ fixed in latest |
| CVE-2024-7353 | Accept Stripe Payments [stripe-payments] < 2.0.87 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.4 | < 2.0.87 | 2.0.87 | 2024-08-06 | ✓ fixed in latest |
| CVE-2023-48285 | Accept Stripe Payments [stripe-payments] < 2.0.80 | Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) | Medium 5.3 | < 2.0.80 | 2.0.80 | 2023-11-23 | ✓ fixed in latest |
| CVE-2023-48286 | Accept Stripe Payments [stripe-payments] < 2.0.80 | Missing Authorization | High 8.2 | < 2.0.80 | 2.0.80 | 2023-11-23 | ✓ fixed in latest |
| CVE-2022-2194 | Accept Stripe Payments [stripe-payments] < 2.0.64 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 4.8 | < 2.0.64 | 2.0.64 | 2022-06-27 | ✓ fixed in latest |
| — | Accept Stripe Payments [stripe-payments] < 2.0.54 | — | Unknown | < 2.0.54 | 2.0.54 | 2022-03-14 | ✓ fixed in latest |
| — | Accept Stripe Payments [stripe-payments] < 2.0.40 | — | Unknown | < 2.0.40 | 2.0.40 | 2021-01-08 | ✓ fixed in latest |
+ 3 more known vulnerabilities
| CVE | Vulnerability | Type | Severity | Affected | Fixed in | Published | Status |
|---|---|---|---|---|---|---|---|
| — | Accept Stripe Payments [stripe-payments] < 2.0.40 | — | Unknown | < 2.0.40 | 2.0.40 | 2021-01-05 | ✓ fixed in latest |
| — | Accept Stripe Payments [stripe-payments] < 2.0.40 | — | Unknown | < 2.0.40 | 2.0.40 | — | ✓ fixed in latest |
| — | Stripe Payments < 2.0.40 - Authenticated Stored Cross-Site Scripting (XSS) | — | Unknown | < 2.0.40 | 2.0.40 | — | ✓ fixed in latest |
How to fix it
Keep Stripe Payments updated — 2.1.1 is the latest version on wordpress.org, and each CVE above lists the exact release that fixed it ("Fixed in").
This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.
Safer / more established alternatives
- WooPayments: Integrated WooCommerce Payments — 800000+ active installs — 68/100 (167) — max PHP 8.4
- WooCommerce PayPal Payments — 800000+ active installs — 56/100 (577) — max PHP 8.4
- WooCommerce Stripe Payment Gateway — 700000+ active installs — 62/100 (236) — max PHP 8.4
- WooCommerce Tax (formerly WooCommerce Shipping & Tax) — 500000+ active installs — 40/100 (105) — max PHP 8.4
- Mollie Payments for WooCommerce — 100000+ active installs — 70/100 (70)
Check your own WordPress site
Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.