CVE-2026-81423
Received Received - Intake

Open Redirect Vulnerability in Accept Stripe Payments WordPress Plugin

Vulnerability report for CVE-2026-81423, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-05

Last updated on: 2026-09-05

Assigner: WPScan

Description

The Accept Stripe Payments WordPress plugin before 2.1.4 does not validate a user-supplied URL before using it in a redirect, allowing unauthenticated attackers to redirect visitors to an arbitrary external website, which can be leveraged for phishing.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-05
Last Modified
2026-09-05
Generated
2026-09-05
AI Q&A
2026-09-05
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
wpsecure accept_stripe_payments to 2.1.4 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects the Accept Stripe Payments WordPress plugin before version 2.1.4. It involves an open redirect issue where the plugin does not validate user-supplied URLs before using them in a redirect. This allows unauthenticated attackers to redirect visitors to arbitrary external websites, which could be used for phishing attacks.

Detection Guidance

Check the installed version of the Accept Stripe Payments plugin in WordPress. If it is below 2.1.4, the system is vulnerable. Use WordPress admin panel or run a command like 'wp plugin list' in the WordPress directory to verify the version.

Impact Analysis

Unauthenticated attackers can exploit this to redirect your website visitors to malicious sites, potentially tricking them into revealing sensitive information like login credentials or payment details. This could harm your site's reputation and lead to loss of user trust.

Compliance Impact

This vulnerability could potentially impact compliance with GDPR and HIPAA by enabling phishing attacks through open redirect flaws. Attackers may trick users into visiting malicious sites, risking unauthorized data exposure or breaches of confidentiality requirements under these regulations.

Mitigation Strategies

Update the Accept Stripe Payments plugin to version 2.1.4 or later immediately. Disable the plugin temporarily if an update is not immediately available, and monitor for suspicious redirect activity in server logs.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-81423. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart