Payload: Insufficient Access Control in Stripe REST Proxy
An authenticated user could perform unintended Stripe operations through the optional Stripe REST proxy. You are affected if ALL of these are true: Your application uses @payloadcms/plugin-stripe. The optional Stripe REST proxy is enabled. An authenticated user can reach the proxy. Deployments that do not enable the Stripe REST proxy are not affected.