---
id: CVE-2026-81424
title: >-
  The Accept Stripe Payments WordPress plugin before 2.1.4 does not verify that
  the product fulfilled when a checkout is completed matches the product the
  authoritative payment was actually made for, checking only that the amount
  paid is a…
summary: >-
  The Accept Stripe Payments WordPress plugin before 2.1.4 does not verify that
  the product fulfilled when a checkout is completed matches the product the
  authoritative payment was actually made for, checking only that the amount
  paid is a…
severity: medium
cvss: 5.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'
cwe:
  - CWE-639
published: '2026-09-05'
updated: '2026-09-08'
sourceUpdated: '2026-09-08T19:09:21.310'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-81424'
references:
  - url: 'https://wpscan.com/vulnerability/64c20ce4-d94d-4f09-8d95-9ba232066f62/'
    label: contact@wpscan.com
tags:
  - nvd
epss: 0.00304
epssPercentile: 0.20601
ingestedAt: '2026-09-06T04:50:00.957Z'
---

## Overview

The Accept Stripe Payments WordPress plugin before 2.1.4 does not verify that the product fulfilled when a checkout is completed matches the product the authoritative payment was actually made for, checking only that the amount paid is at least the referenced product's price, allowing unauthenticated attackers who complete a genuine payment to obtain fulfilment for a different, equal- or lower-priced product than the one they paid for.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
