cleantalk
Vulnerabilities and Security Researches

Vulnerabilities and security researches foreasy-paypal-donation easy-paypal-donation

Direction: descending
May 09, 2025

Accept Donations with PayPal # CVE-2025-47517

CVE, Research URL

CVE-2025-47517

Date
May 07, 2025
Research Description
Cross-Site Request Forgery (CSRF) vulnerability in Scott Paterson Accept Donations with PayPal allows Stored XSS. This issue affects Accept Donations with PayPal: from n/a through 1.4.5.
Affected versions
Min -, max -.
Status
vulnerable
Feb 24, 2025

Accept Donations with PayPal # CVE-2024-13728

CVE, Research URL

CVE-2024-13728

Date
Feb 23, 2025
Research Description
The Accept Donations with PayPal & Stripe plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the rf parameter in all versions up to, and including, 1.4.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
Affected versions
Min -, max -.
Status
vulnerable
Jun 07, 2024

Accept Donations with PayPal # CVE-2021-24572

CVE, Research URL

CVE-2021-24572

Date
Nov 01, 2021
Research Description
The Accept Donations with PayPal WordPress plugin before 1.3.1 provides a function to create donation buttons which are internally stored as posts. The deletion of a button is not CSRF protected and there is no control to check if the deleted post was a button post. As a result, an attacker could make logged in admins delete arbitrary posts
Affected versions
Min -, max -.
Status
vulnerable

Accept Donations with PayPal # CVE-2021-24989

CVE, Research URL

CVE-2021-24989

Date
Jan 24, 2022
Research Description
The Accept Donations with PayPal WordPress plugin before 1.3.4 does not have CSRF check in place and does not ensure that the post to be deleted belongs to the plugin, allowing attackers to make a logged in admin delete arbitrary posts from the blog
Affected versions
Min -, max -.
Status
vulnerable

Accept Donations with PayPal # CVE-2021-24815

CVE, Research URL

CVE-2021-24815

Date
Nov 17, 2021
Research Description
The Accept Donations with PayPal WordPress plugin before 1.3.2 does not escape the Amount Menu Name field of created Buttons, which could allow a high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.
Affected versions
Min -, max -.
Status
vulnerable

Accept Donations with PayPal # CVE-2021-24570

CVE, Research URL

CVE-2021-24570

Date
Nov 01, 2021
Research Description
The Accept Donations with PayPal WordPress plugin before 1.3.1 offers a function to create donation buttons, which internally are posts. The process to create a new button is lacking a CSRF check. An attacker could use this to make an authenticated admin create a new button. Furthermore, one of the Button field is not escaped before being output in an attribute when editing a Button, leading to a Stored Cross-Site Scripting issue as well.
Affected versions
Min -, max -.
Status
vulnerable