Vulnerabilities and security researches forwp-payment-form wp-payment-form
Direction: ascendingSimple Payment Donations & Subscriptions Plugin by Paymattic – Best Payments Plugin for WP # eb8c3b246ed634de3b474b2fd400a792d258a3ea
- CVE, Research URL
- Home page URL
- Application
-
Simple Payment Donations & Subscriptions Plugin by Paymattic – Best Payments Plugin for WP
- Date
- Aug 10, 2022
- Research Description
- Paymattic – Secure, Simple Payment & Donation with Subscription Payments, Recurring Donations, Customer Management [wp-payment-form] < 4.2.1 WordPress Best Payments Plugin for WP plugin <= 4.2.0 - Reflected Cross-Site Scripting (XSS) vulnerability Reflected Cross-Site Scripting (XSS) vulnerability discovered by WPScan in WordPress Best Payments Plugin for WP plugin (versions <= 4.2.0). Update the WordPress Best Payments Plugin for WP plugin to the latest available version (at least 4.2.1).
- Affected versions
-
max 4.2.1.
- Status
-
vulnerable
Simple Payment Donations & Subscriptions Plugin by Paymattic – Best Payments Plugin for WP # CVE-2022-2565
- CVE, Research URL
- Home page URL
- Application
-
Simple Payment Donations & Subscriptions Plugin by Paymattic – Best Payments Plugin for WP
- Date
- Sep 05, 2022
- Research Description
- The Simple Payment Donations & Subscriptions WordPress plugin before 4.2.1 does not sanitise and escape user input given in its forms, which could allow unauthenticated attackers to perform Cross-Site Scripting attacks against admins
- Affected versions
-
max 4.2.1.
- Status
-
vulnerable
Simple Payment Donations & Subscriptions Plugin by Paymattic – Best Payments Plugin for WP # CVE-2026-42655
- CVE, Research URL
- Home page URL
- Application
-
Simple Payment Donations & Subscriptions Plugin by Paymattic – Best Payments Plugin for WP
- Date
- Jun 16, 2026
- Research Description
- Unauthenticated Bypass Vulnerability in Best Payments Plugin for WP <= 4.6.19 versions.
- Affected versions
-
max 4.6.20.
- Status
-
vulnerable
Simple Payment Donations & Subscriptions Plugin by Paymattic – Best Payments Plugin for WP # 9ff8a652-2340-476d-8430-70b203c023e1
- CVE, Research URL
- Home page URL
- Application
-
Simple Payment Donations & Subscriptions Plugin by Paymattic – Best Payments Plugin for WP
- Date
- -
- Research Description
- Paymattic – Secure, Simple Payment & Donation with Subscription Payments, Recurring Donations, Customer Management [wp-payment-form] < 4.2.1 Best Payments Plugin for WP < 4.2.1 - Reflected Cross-Site Scripting The plugin does not escape an URL before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting
- Affected versions
-
max 4.2.1.
- Status
-
vulnerable
Simple Payment Donations & Subscriptions Plugin by Paymattic – Best Payments Plugin for WP # b6106dd9bc47fc566edd8b2a51e8e46221dd1b18
- CVE, Research URL
- Home page URL
- Application
-
Simple Payment Donations & Subscriptions Plugin by Paymattic – Best Payments Plugin for WP
- Date
- Aug 10, 2022
- Research Description
- Paymattic – Secure, Simple Payment & Donation with Subscription Payments, Recurring Donations, Customer Management [wp-payment-form] < 4.2.1 Simple Payment Donations <= 4.2.0 - Reflected Cross-Site Scripting The Simple Payment Donations plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 4.2.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
- Affected versions
-
max 4.2.1.
- Status
-
vulnerable
Simple Payment Donations & Subscriptions Plugin by Paymattic – Best Payments Plugin for WP # CVE-2026-89411
- CVE, Research URL
- Home page URL
- Application
-
Simple Payment Donations & Subscriptions Plugin by Paymattic – Best Payments Plugin for WP
- Date
- Sep 28, 2026
- Research Description
- The Paymattic WordPress plugin from 4.6.20 before 4.6.26 does not verify that a confirmed Stripe payment belongs to the order it is applied to, allowing unauthenticated users to mark an arbitrary pending order as paid by confirming a smaller payment of their own against it.
- Affected versions
-
Min 4.6.20, max 4.6.26.
- Status
-
vulnerable