CVE-2021-47983
The Accept Stripe Payments plugin through version 2.0.39 contains a stored cross-site scripting vulnerability in its administrative settings because it fails to properly sanitize inputs and escape outputs. Attackers with administrator privileges can inject malicious scripts that will run when other users view affected pages, though this issue only impacts WordPress multisite setups or installations with the unfiltered_html capability disabled. The vulnerability remains unfixed as of the stated version.
Based on public CVE data (MITRE/NVD).