The Stripe Payment Plugin for WooCommerce, used in WordPress, has an issue in the versions up to and including 3.5.9. It is vulnerable to Reflected Cross-Site Scripting, due to a lack of input sanitization and output escaping. This means that unauthenticated attackers can inject malicious web scripts into pages, which then execute if a user is tricked into performing an action such as clicking a link.