cleantalk
Vulnerabilities and Security Researches

Simple Payment Donations & Subscriptions Plugin by Paymattic – Best Payments Plugin for WP, b6106dd9bc47fc566edd8b2a51e8e46221dd1b18

Published on
Aug 10, 2022
Research Description
Paymattic &#8211; Secure, Simple Payment &amp; Donation with Subscription Payments, Recurring Donations, Customer Management [wp-payment-form] < 4.2.1 Simple Payment Donations <= 4.2.0 - Reflected Cross-Site Scripting The Simple Payment Donations plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 4.2.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
Affected versions
max 4.2.1.
Status
vulnerable