WordPress Plugin Stripe Payments 2.0.39 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts through the AcceptStripePayments-settings[currency_code] parameter. Attackers can submit POST requests to /wp-admin/options.php with script payloads in the currency_code field to execute arbitrary JavaScript in administrator browsers when settings are viewed.
Metrics
Affected Vendors & Products
References
History
Mon, 08 Jun 2026 02:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | WordPress Plugin Stripe Payments 2.0.39 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts through the AcceptStripePayments-settings[currency_code] parameter. Attackers can submit POST requests to /wp-admin/options.php with script payloads in the currency_code field to execute arbitrary JavaScript in administrator browsers when settings are viewed. | |
| Title | WordPress Plugin Stripe Payments 2.0.39 Stored XSS via currency_code | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published: 2026-06-08T01:55:26.047Z
Updated: 2026-06-08T01:55:26.047Z
Reserved: 2026-06-07T22:47:03.333Z
Link: CVE-2021-47983
No data.
Status : Deferred
Published: 2026-06-08T02:16:22.363
Modified: 2026-06-08T14:59:44.750
Link: CVE-2021-47983
No data.
ReportizFlow