Input validation vulnerability in Stripe Payment Plugin for WooCommerce 3.5.9

The Stripe Payment Plugin for WooCommerce, used in WordPress, has an issue in the versions up to and including 3.5.9. It is vulnerable to Reflected Cross-Site Scripting, due to a lack of input sanitization and output escaping. This means that unauthenticated attackers can inject malicious web scripts into pages, which then execute if a user is tricked into performing an action such as clicking a link.

Detected in:

Stripe Payment Gateway for WooCommerce fixed vulnerable versions:
Stripe Payment Plugin for WooCommerce fixed vulnerable versions: >= * <= 3.5.9

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.