That is true, but the point is that the only thing that is going to be compromised is the data that would be going to Stripe.
I know it is shocking to many of you to hear this, but the data Stripe collects is not really the most sensitive information on the Internet.
The point of the iframe is to contain the damage from any possible compromise. If PAYMENTIFRAME.COM is insecure (heh), you still aren't going to lose user sessions to your actual application.