Paymentsplugin operates a WordPress payment-processing plugin (WP Full Stripe Free) that integrates payment handling into WordPress sites, exposing the plugin to web-application input-handling risks. The observed vulnerability pattern centers on cross-site scripting and cross-site request forgery weaknesses, reflecting the challenges of sanitizing untrusted input and validating state-changing requests in plugin environments where third-party code interacts with payment flows. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Paymentsplugin over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-47667HIGH Cross-Site Request Forgery (CSRF) vulnerability in Mammothology WP Full Stripe Free.This issue affects WP Full Stripe Free: from n/a through 7.0.16. | Nov 18, 2023 | 8.8 | 24 | NO | NO |
CVE-2023-46088MEDIUM Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Mammothology WP Full Stripe Free plugin <= 1.6.1 versions. | Oct 26, 2023 | 4.8 | 16 | NO | NO |
CVE-2023-28934MEDIUM Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Mammothology WP Full Stripe Free plugin <= 1.6.1 versions. | Aug 8, 2023 | 4.8 | 16 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Paymentsplugin.
Media articles that mention a CVE ID that affects a product developed by Paymentsplugin — matched by CVE ID, not by vendor name.