What is CVE-2026-16734?
The WP Full Pay Stripe payment plugin for WordPress before version 8.5.2 fails to verify ownership of Stripe payment intents via two unauthenticated AJAX actions. This flaw allows unauthorized visitors to manipulate payment data using a nonce embedded in public pages. Immediate update to the latest version is recommended.
Azərbaycanca: WordPress üçün WP Full Pay Stripe ödəniş plaqini 8.5.2 versiyasından əvvəl autentifikasiya olunmamış AJAX əməliyyatlarında Stripe ödəniş niyyətinə sahibliyi yoxlamır. Bu zəiflik səhifədəki nonce vasitəsilə icazəsiz ziyarətçilərə ödəniş məlumatlarını manipulyasiya etməyə imkan verir. Plaqini dərhal ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-862; shared vendor: Stripe
FAQ2
Through what type of unauthenticated operations can CVE-2026-16734 be exploited in the WP Full Pay Stripe plugin?
This flaw can be exploited via two unauthenticated AJAX actions.
To mitigate CVE-2026-16734, to which version should the WP Full Pay Stripe plugin be updated?
The plugin should be updated to the latest version, as the vulnerability affects versions before 8.5.2.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.