Sceawere

Vulnerability Detail

CVE-2026-89100UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Stripe WooCommerce Reflected XSS

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.1
Creation Date
3h ago
Vendor
paymentplugins
Product
Payment Plugins for Stripe WooCommerce
Attack Type
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Attack Complexity
LOW

Narrative and Response

Description

The Payment Plugins for Stripe WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via '#response' URL Fragment in all versions up to, and including, 4.0.17 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Exploitation requires that the 'Generic Errors' setting is unchecked, causing getErrorMessage() to return the raw Stripe error string unchanged rather than substituting a mapped safe message.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.1",
  "pubDate": "2026-10-10T07:16:41.927Z",
  "pubdate": "2026-10-10T07:16:41.927Z",
  "executiveSummary": "The Payment Plugins for Stripe WooCommerce plugin for WordPress, in versions up to and including 4.0.17, is susceptible to a Reflected Cross-Site Scripting (XSS) vulnerability.\nThis vulnerability stems from the improper handling of the '#response' URL fragment, which fails to undergo adequate input sanitization or output escaping before being rendered in the Document Object Model (DOM).\nAn unauthenticated attacker can exploit this flaw by crafting malicious links that include arbitrary JavaScript payloads. When a user interacts with these links, the injected scripts execute within the context of the victim's session, leading to potential account compromise, session hijacking, or unauthorized actions performed on the site.\nThe attack is contingent upon specific configuration: the 'Generic Errors' setting must be unchecked. Under this condition, the internal function getErrorMessage() returns raw, unvalidated error strings directly from the Stripe API or related sources. This creates an execution sink for user-supplied data transmitted via URL fragments.\nGiven the nature of XSS, this vulnerability represents a significant security risk to both administrators and end-users of the affected WooCommerce platform.",
  "technicalDetails": "The vulnerability resides in the way the Payment Plugins for Stripe WooCommerce plugin manages error reporting and URL parameter processing. Specifically, the application logic processes the '#response' URL fragment, which is often used in web applications to handle client-side state or asynchronous feedback. Because the application fails to perform necessary output encoding or sanitization on this fragment, it treats the input as trusted data.\nThe root cause is identified within the getErrorMessage() function. When the 'Generic Errors' setting in the plugin configuration is disabled, the function bypasses its standard security logic—which typically substitutes potentially malicious or verbose error strings with mapped, safe, and generic error messages. Instead, it returns the raw string returned by the underlying Stripe response mechanism. By manipulating the URL fragment, an attacker can inject a payload that is subsequently reflected back to the user's browser without being neutralized.\nThe attack flow begins when an attacker identifies the URL structure utilized by the plugin to handle Stripe response messaging. The attacker constructs a URL containing a '#response' fragment populated with a cross-site scripting payload (e.g., <script>alert(document.cookie)</script>). This URL is then distributed to the target user through phishing, social engineering, or other delivery vectors.\nUpon clicking the link, the browser resolves the URL, and the client-side JavaScript of the plugin retrieves the malicious string from the fragment. Because of the insufficient sanitization and the configuration state mentioned, the payload is injected directly into the HTML context. The browser, trusting the origin, executes the arbitrary JavaScript.\nThis vulnerability is classified as Reflected XSS as it does not require the payload to be stored persistently in the database, though it relies on the user's interaction with the specific URL. The impact is severe, as the script runs within the security domain of the WordPress site. Consequently, an attacker can access sensitive session cookies, perform unauthorized API requests, redirect the user, or modify the visual content of the page to conduct further credential harvesting. No special privileges are required to initiate the attack, making it accessible to unauthenticated remote adversaries."
}
CVE-2026-89100: Stripe WooCommerce Reflected XSS (MEDIUM Severity, CVSS: 6.1) | Sceawere