Known Vulnerabilities for Plugin-stripe by @payloadcms
Listed below are 10 of the newest known vulnerabilities associated with "Plugin-stripe" by "@payloadcms".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-105850 json | Payload is a free and open source headless content management system. In @payloadcms/plugin-ecommerce versions before 3.90.0 ... | Not Provided | 2026-10-06 | 2026-10-06 |
| CVE-2026-105848 json | Payload is a free and open source headless content management system. In @payloadcms/plugin-stripe versions before 3.90.0 and... | Not Provided | 2026-10-06 | 2026-10-06 |
| CVE-2026-97661 json | The Business Essentials for Contact Form 7 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'gateway' Fo... | Not Provided | 2026-10-01 | 2026-10-01 |
| CVE-2026-94432 json | The Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress plugin for WordPress is vulnerable to Inse... | Not Provided | 2026-10-02 | 2026-10-03 |
| CVE-2026-91019 json | The Event Booking Manager for WooCommerce WordPress plugin before 5.6.0 does not restrict who can view its stored payment ga... | Not Provided | 2026-09-17 | 2026-09-17 |
| CVE-2026-90987 json | The Easy PayPal & Stripe Buy Now Button WordPress plugin before 2.0.6 does not derive the payment amount on the server, takin... | Not Provided | 2026-10-02 | 2026-10-02 |
| CVE-2026-90650 json | The MotoPress Hotel Booking plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Stripe Webhook event ob... | Not Provided | 2026-09-15 | 2026-09-15 |
| CVE-2026-89411 json | The Paymattic WordPress plugin from 4.6.20 before 4.6.26 does not verify that a confirmed Stripe payment belongs to the order... | Not Provided | 2026-09-28 | 2026-09-28 |
| CVE-2026-81424 json | The Accept Stripe Payments WordPress plugin before 2.1.4 does not verify that the product fulfilled when a checkout is comple... | Not Provided | 2026-09-05 | 2026-09-06 |
| CVE-2026-81423 json | The Accept Stripe Payments WordPress plugin before 2.1.4 does not validate a user-supplied URL before using it in a redirect,... | Not Provided | 2026-09-05 | 2026-09-06 |