
CVE-2026-1295 The Buy Now Plus – Buy Now buttons for Stripe plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'buynowplus' shortcode in all versions up to, an… https://www.cve.org/CVERecord?id=CVE-2026-1295
Post summary
The text announces CVE-2026-1295, a stored XSS flaw in the Stripe WordPress plugin triggered by the 'buynowplus' shortcode, with no indications of PoC, exploit code, active exploitation, or patch details.
