# Paymattic – Secure, Simple Payment & Donation with Subscription Payments, Recurring Donations, Customer Management <= 4.6.27 - Unauthenticated Stored Cross-Site Scripting via Stripe Billing Details

- **ID:** WPSEC-2026-0732
- **Plugin:** Paymattic – Secure, Simple Payment & Donation with Subscription Payments, Recurring Donations, Customer Management (`wp-payment-form`), https://wordpress.org/plugins/wp-payment-form/
- **Affected versions:** all versions before 4.6.28
- **Fixed in:** 4.6.28 (Update to 4.6.28 or later.)
- **Severity:** High 7.2 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N)
- **Weakness:** CWE-79
- **Usage among sites WPSec scans:** plugin Low, affected versions None seen (as of 2026-10-10)
- **Attack surface analysis:** https://attacksurface.wpsec.com/plugin/wp-payment-form
- **Fix released:** 2026-10-09
- **Published:** 2026-10-10
- **URL:** https://wpsec.com/vuln/WPSEC-2026-0732/

## Description

The Paymattic – Secure, Simple Payment & Donation with Subscription Payments, Recurring Donations, Customer Management plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Stripe billing and shipping details (the '__stripe_billing_address_json' and '__stripe_shipping_address_json' form fields, and the billing name, phone, email and address returned from Stripe checkout) in all versions up to, and including, 4.6.27, due to insufficient input sanitization and output escaping. These values are saved with the form submission, and the billing name may also be saved as the customer name. They are later shown unescaped in the admin entry view, reports and customer lists. This makes it possible for unauthenticated attackers who submit a payment form to inject arbitrary web scripts that execute whenever an administrator views the affected entry or report pages.

## References

- https://wpsec.com/vuln/WPSEC-2026-0732/
- https://plugins.svn.wordpress.org/wp-payment-form/tags/4.6.28/
- https://wordpress.org/plugins/wp-payment-form/

Source: WPSec, https://wpsec.com/vuln/WPSEC-2026-0732/

License: CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/). Free to use, share and adapt, also commercially, if you credit WPSec and link to this advisory.
