Paymattic – Secure, Simple Payment & Donation with Subscription Payments, Recurring Donations, Customer Management <= 4.6.27 - Unauthenticated Stored Cross-Site Scripting via Stripe Billing Details

High 7.2 CWE-79Fixed in 4.6.28
ID
WPSEC-2026-0732
Plugin
Paymattic – Secure, Simple Payment & Donation with Subscription Payments, Recurring Donations, Customer Management (wp-payment-form)
Affected
all versions before 4.6.28
Remediation
Update to 4.6.28 or later.
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
Weakness
CWE-79
Usage
Plugin Low · Affected versions None seen among sites WPSec scans, 2026-10-10
Attack surface
Paymattic – Secure, Simple Payment & Donation with Subscription Payments, Recurring Donations, Customer Management on WPSec AttackSurface
Fix released
Published

Description

The Paymattic – Secure, Simple Payment & Donation with Subscription Payments, Recurring Donations, Customer Management plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Stripe billing and shipping details (the '__stripe_billing_address_json' and '__stripe_shipping_address_json' form fields, and the billing name, phone, email and address returned from Stripe checkout) in all versions up to, and including, 4.6.27, due to insufficient input sanitization and output escaping. These values are saved with the form submission, and the billing name may also be saved as the customer name. They are later shown unescaped in the admin entry view, reports and customer lists. This makes it possible for unauthenticated attackers who submit a payment form to inject arbitrary web scripts that execute whenever an administrator views the affected entry or report pages.

References

Published by WPSec. Provided as is, without warranty. Corrections: contact us.

This advisory as JSON or Markdown · All advisories: JSON, RSS

License: CC BY 4.0