Stripe Green Downloads Wordpress Plugin 2.03 contains a persistent cross-site scripting vulnerability allowing remote attackers to inject malicious scripts in button label fields. Attackers can exploit input parameters to execute arbitrary scripts, potentially leading to session hijacking and application module manipulation.
History

Tue, 03 Feb 2026 15:00:00 +0000

Type Values Removed Values Added
First Time appeared Halfdata
Halfdata stripe Green Downloads
Wordpress
Wordpress wordpress
Vendors & Products Halfdata
Halfdata stripe Green Downloads
Wordpress
Wordpress wordpress

Mon, 02 Feb 2026 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 01 Feb 2026 12:30:00 +0000

Type Values Removed Values Added
Description Stripe Green Downloads Wordpress Plugin 2.03 contains a persistent cross-site scripting vulnerability allowing remote attackers to inject malicious scripts in button label fields. Attackers can exploit input parameters to execute arbitrary scripts, potentially leading to session hijacking and application module manipulation.
Title Stripe Green Downloads Wordpress Plugin 2.03 Persistent XSS via Settings
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N'}

cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-02-02T19:00:14.357Z

Reserved: 2025-12-26T16:41:38.890Z

Link: CVE-2022-50797

cve-icon Vulnrichment

Updated: 2026-02-02T19:00:07.277Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-02-01T13:15:56.940

Modified: 2026-02-03T16:44:36.630

Link: CVE-2022-50797

cve-icon Redhat

No data.