Vulnerabilities and security researches foreasy-paypal-donation easy-paypal-donation
Direction: descendingMay 09, 2025
Accept Donations with PayPal # CVE-2025-47517
- CVE, Research URL
- Home page URL
- Application
- Date
- May 07, 2025
- Research Description
- Cross-Site Request Forgery (CSRF) vulnerability in Scott Paterson Accept Donations with PayPal allows Stored XSS. This issue affects Accept Donations with PayPal: from n/a through 1.4.5.
- Affected versions
-
Min -, max -.
- Status
-
vulnerable
Feb 24, 2025
Accept Donations with PayPal # CVE-2024-13728
- CVE, Research URL
- Home page URL
- Application
- Date
- Feb 23, 2025
- Research Description
- The Accept Donations with PayPal & Stripe plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the rf parameter in all versions up to, and including, 1.4.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
- Affected versions
-
Min -, max -.
- Status
-
vulnerable
Jun 07, 2024
Accept Donations with PayPal # CVE-2021-24572
- CVE, Research URL
- Home page URL
- Application
- Date
- Nov 01, 2021
- Research Description
- The Accept Donations with PayPal WordPress plugin before 1.3.1 provides a function to create donation buttons which are internally stored as posts. The deletion of a button is not CSRF protected and there is no control to check if the deleted post was a button post. As a result, an attacker could make logged in admins delete arbitrary posts
- Affected versions
-
Min -, max -.
- Status
-
vulnerable
Accept Donations with PayPal # CVE-2021-24989
- CVE, Research URL
- Home page URL
- Application
- Date
- Jan 24, 2022
- Research Description
- The Accept Donations with PayPal WordPress plugin before 1.3.4 does not have CSRF check in place and does not ensure that the post to be deleted belongs to the plugin, allowing attackers to make a logged in admin delete arbitrary posts from the blog
- Affected versions
-
Min -, max -.
- Status
-
vulnerable
Accept Donations with PayPal # CVE-2021-24815
- CVE, Research URL
- Home page URL
- Application
- Date
- Nov 17, 2021
- Research Description
- The Accept Donations with PayPal WordPress plugin before 1.3.2 does not escape the Amount Menu Name field of created Buttons, which could allow a high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.
- Affected versions
-
Min -, max -.
- Status
-
vulnerable
Accept Donations with PayPal # CVE-2021-24570
- CVE, Research URL
- Home page URL
- Application
- Date
- Nov 01, 2021
- Research Description
- The Accept Donations with PayPal WordPress plugin before 1.3.1 offers a function to create donation buttons, which internally are posts. The process to create a new button is lacking a CSRF check. An attacker could use this to make an authenticated admin create a new button. Furthermore, one of the Button field is not escaped before being output in an attribute when editing a Button, leading to a Stored Cross-Site Scripting issue as well.
- Affected versions
-
Min -, max -.
- Status
-
vulnerable