Stripe Payment Forms by WP Full Pay <= 8.4.3 - Missing Authorization to Unauthenticated Payment Record Manipulation via 'paymentIntentId' Parameter
Strategic Overview
- Status
- Patched in 8.5.0
- Affected Plugin
- Stripe Payment Forms by WP Full Pay – Accept Credit Card Payments, Donations & Subscriptions
- Affected Version
<= 8.4.3- CVSS
- 5.3Medium
- Weakness type
- CWE-862 · Missing Authorization
- CVE
CVE-2026-12432
At a glance
CVE-2026-12432 is a medium-severity Missing Authorization vulnerability in the Stripe Payment Forms by WP Full Pay WordPress plugin, affecting versions <= 8.4.3. It carries a CVSS score of 5.3 (reachable over the network; low attack complexity). Exploitation requires no authentication. The issue is fixed in version 8.5.0; sites on affected versions should update now. Disclosed June 2026, reported by Netwurm.
Vulnerability Overview
The WP Full Stripe Free plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 8.4.3 via the wpfs_update_failed_payment_status AJAX action. The handler is registered through both wp_ajax_ and wp_ajax_nopriv_ hooks and the underlying update_failed_payment_status() function performs no capability check, no nonce verification, and no logged-in check before calling $this->db->updatePaymentByEventId() with attacker-controlled POST parameters. This makes it possible for unauthenticated attackers who can obtain a valid Stripe Payment Intent ID for the target site (Payment Intent IDs are exposed to the customer browser during normal Stripe.js checkout flows) to manipulate payment records in the site's database, marking previously successful payments as failed and overwriting failure codes and messages with attacker-supplied values.
Technical Analysis
The vector marks this flaw as remotely reachable over the network, with low attack complexity — no special timing or configuration is needed, and no privileges on the target site, and no interaction from a victim user.
CWE-862: Missing Authorization
Stripe Payment Forms by WP Full Pay <= 8.4.3 carries this weakness at update_failed_payment_status(), and reaching it takes no account at all. A missing authorization check means a function is reachable by anyone who can reach the endpoint, because the code never asks whether the caller is allowed to perform the action.
Any user who can reach the endpoint gets to run an action reserved for higher-privileged roles, from reading protected data to changing settings or content. For Stripe Payment Forms by WP Full Pay the fix is 8.5.0: builds <= 8.4.3 are affected, anything from 8.5.0 onward is not.
Remediation
Update to version 8.5.0, or a newer patched version
How does WordSec protect against this?
This one needs no account at all, which puts it outside what login hardening can reach; WordSec's login security narrows the account-level paths around it, and the firewall is what inspects the request itself. None of that substitutes for the fix: Stripe Payment Forms by WP Full Pay 8.5.0 closes this, and updating the plugin is the step that ends it.
- Login Security
- Alerts
External References
Related records
Same weakness class
Other vulnerabilities in Stripe Payment Forms by WP Full Pay – Accept Credit Card Payments, Donations & Subscriptions
- 7.5CVE-2025-9322: Stripe Payment Forms <= 8.3.1 SQL Injection
CVE-2025-9322 - 7.2CVE-2026-61960: Stripe Payment Forms by WP Full Pay Stored XSS
CVE-2026-61960 - 4.9CVE-2025-58789: WP Full Stripe Free <= 8.2.5 SQL Injection
CVE-2025-58789 - 4.4CVE-2023-46088: WP Full Stripe Free <= 7.0.5 Stored XSS
CVE-2023-46088 - 4.4CVE-2023-28934: WP Full Stripe Free <= 7.0.5 Stored XSS
CVE-2023-28934 - 4.3CVE-2023-47667: WP Full Stripe Free <= 7.0.17 CSRF
CVE-2023-47667
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C