CVE-2026-77758
MEDIUM
NVD
CVSS Score
5.3
Severity
MEDIUM
Published
Aug 26, 2026
Vendor
unknown
Description
The Stripe Payment Forms by WP Full Pay WordPress plugin before 8.5.1 does not properly verify that a customer portal session has completed its confirmation step before returning data, allowing unauthenticated users to read another customer's subscription and billing information.