THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-81424 (MEDIUM 5.3) — The Accept Stripe Payments WordPress plugin before 2.1.4 does not verify that the product fulfilled when a checkout is completed matches the product the authoritative payment was actually made for, checking only that the amount paid is at least the referenced product's price, all

[NVD] CVE-2026-81424 (MEDIUM 5.3) — The Accept Stripe Payments WordPress plugin before 2.1.4 does not verify that the product fulfilled when a checkout is completed matches the product the authoritative payment was actually made for, checking only that the amount paid is at least the referenced product's price, all

mednvdPublished 2026-09-05

CVE-2026-81424 CVSS: 5.3 MEDIUM Published: 2026-09-05T07:17:12.997

The Accept Stripe Payments WordPress plugin before 2.1.4 does not verify that the product fulfilled when a checkout is completed matches the product the authoritative payment was actually made for, checking only that the amount paid is at least the referenced product's price, allowing unauthenticated attackers who complete a genui

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-81424