HIGH
WP Full Pay
CVE published 2026-08-06
CVE-2026-16734
The Stripe Payment Forms by WP Full Pay WordPress plugin before 8.5.2 has a vulnerability allowing unauthenticated visitors to change payment intent amounts due to missing ownership checks in two payment-form AJAX actions. This vulnerability exists because an ownership check added in version 8.5.0 was only applied to one payment-intent handler, leaving pricing recalculation and payment-intent update actio [truncated]