PT-2026-47229 · Mra13 · Accept Stripe Payments
Published
2026-06-08
·
Updated
2026-06-08
·
CVE-2021-47983
CVSS v3.1
6.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N |
WordPress Plugin Stripe Payments 2.0.39 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts through the AcceptStripePayments-settings[currency code] parameter. Attackers can submit POST requests to /wp-admin/options.php with script payloads in the currency code field to execute arbitrary JavaScript in administrator browsers when settings are viewed.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Accept Stripe Payments