CVE-2023-47239 – WordPress Easy PayPal Shopping Cart Plugin <= 1.1.10 is vulnerable to Cross Site Scripting (XSS)
https://notcve.org/view.php?id=CVE-2023-47239
03 Nov 2023 — Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Scott Paterson Easy PayPal Shopping Cart plugin <= 1.1.10 versions. Vulnerabilidad de Cross-Site Scripting (XSS) autenticada (con permisos de colaboradores o superiores) almacenada en el complemento Scott Paterson Easy PayPal Shopping Cart en versiones <=1.1.10. The Easy PayPal Shopping Cart plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode in all versions up to, and including, 1.1.10 due to... • https://patchstack.com/database/vulnerability/easy-paypal-shopping-cart/wordpress-easy-paypal-shopping-cart-plugin-1-1-10-cross-site-scripting-xss-vulnerability?_s_id=cve • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2023-24405 – WordPress Contact Form 7 – PayPal & Stripe Add-on Plugin <= 1.9.3 is vulnerable to Cross Site Request Forgery (CSRF)
https://notcve.org/view.php?id=CVE-2023-24405
17 Mar 2023 — Cross-Site Request Forgery (CSRF) vulnerability in Scott Paterson Contact Form 7 – PayPal & Stripe Add-on plugin <= 1.9.3 versions. The Contact Form 7 – PayPal & Stripe Add-on plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.9.3. This is due to missing or incorrect nonce validation on one of its functions. This makes it possible for unauthenticated attackers to invoke that function via a forged request granted they can trick a site administrator into perfo... • https://patchstack.com/database/vulnerability/contact-form-7-paypal-add-on/wordpress-contact-form-7-paypal-stripe-add-on-plugin-1-9-3-cross-site-request-forgery-csrf-vulnerability?_s_id=cve • CWE-352: Cross-Site Request Forgery (CSRF) •
CVE-2023-24395 – WordPress Contact Form 7 Redirect & Thank You Page Plugin <= 1.0.3 is vulnerable to Cross Site Request Forgery (CSRF)
https://notcve.org/view.php?id=CVE-2023-24395
15 Mar 2023 — Cross-Site Request Forgery (CSRF) vulnerability in Scott Paterson Contact Form 7 Redirect & Thank You Page plugin <= 1.0.3 versions. The Contact Form 7 Redirect & Thank You Page plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0.3. This is due to missing or incorrect nonce validation on the cf7rl_admin_table function. This makes it possible for unauthenticated attackers to modify the plugin's settings via a forged request granted they can trick a site admi... • https://patchstack.com/database/vulnerability/cf7-redirect-thank-you-page/wordpress-contact-form-7-redirect-thank-you-page-plugin-1-0-3-cross-site-request-forgery-csrf-vulnerability?_s_id=cve • CWE-352: Cross-Site Request Forgery (CSRF) •
CVE-2022-4628 – Easy PayPal Buy Now Button < 1.7.4 - Contributor+ Stored XSS in Shortcode
https://notcve.org/view.php?id=CVE-2022-4628
19 Jan 2023 — The Easy PayPal Buy Now Button WordPress plugin before 1.7.4 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks The Easy PayPal Buy Now Button plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in versions up to, and including, 1.7.3 due to insufficient input sanitization and o... • https://wpscan.com/vulnerability/6ae719da-c43c-4b3a-bb8a-efa1de20100a • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2021-24989 – Accept Donations with PayPal < 1.3.4 - Arbitrary Post Deletion via CSRF
https://notcve.org/view.php?id=CVE-2021-24989
09 Dec 2021 — The Accept Donations with PayPal WordPress plugin before 1.3.4 does not have CSRF check in place and does not ensure that the post to be deleted belongs to the plugin, allowing attackers to make a logged in admin delete arbitrary posts from the blog El plugin Accept Donations with PayPal de WordPress versiones anteriores a 1.3.4, no presenta una comprobación CSRF y no asegura de que la entrada que va a ser eliminada pertenece al plugin, permitiendo a atacantes hacer que un administrador conectado elimine en... • https://wpscan.com/vulnerability/82c2ead1-1d3c-442a-ae68-359a4748447f • CWE-352: Cross-Site Request Forgery (CSRF) •
CVE-2021-24815 – Paypal Donation < 1.3.2 - Admin+ Stored Cross-Site Scripting
https://notcve.org/view.php?id=CVE-2021-24815
18 Oct 2021 — The Accept Donations with PayPal WordPress plugin before 1.3.2 does not escape the Amount Menu Name field of created Buttons, which could allow a high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed. El plugin Accept Donations with PayPal de WordPress versiones anteriores a 1.3.2, no escapa del campo Amount Menu Name de los botones creados, que podría permitir a un usuario con altos privilegios llevar a cabo ataques de tipo Cross-Site Scripting ... • https://wpscan.com/vulnerability/08f4ebf5-6bbe-4fb0-a9d2-c8a994afe39b • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2021-24572 – Paypal Donation < 1.3.1 - CSRF to Arbitrary Post Deletion
https://notcve.org/view.php?id=CVE-2021-24572
04 Oct 2021 — The Accept Donations with PayPal WordPress plugin before 1.3.1 provides a function to create donation buttons which are internally stored as posts. The deletion of a button is not CSRF protected and there is no control to check if the deleted post was a button post. As a result, an attacker could make logged in admins delete arbitrary posts El plugin Accept Donations with PayPal de WordPress versiones anteriores a 1.3.1, proporciona una función para crear botones de donación que se almacenan internamente co... • https://wpscan.com/vulnerability/7b1ebd26-ea8b-448c-a775-66a04102e44f • CWE-352: Cross-Site Request Forgery (CSRF) •
CVE-2021-24570 – Paypal Donation < 1.3.1 - CSRF to Stored Cross-Site Scripting
https://notcve.org/view.php?id=CVE-2021-24570
04 Oct 2021 — The Accept Donations with PayPal WordPress plugin before 1.3.1 offers a function to create donation buttons, which internally are posts. The process to create a new button is lacking a CSRF check. An attacker could use this to make an authenticated admin create a new button. Furthermore, one of the Button field is not escaped before being output in an attribute when editing a Button, leading to a Stored Cross-Site Scripting issue as well. El plugin Accept Donations with PayPal de WordPress versiones anterio... • https://plugins.trac.wordpress.org/changeset/2608073 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CWE-352: Cross-Site Request Forgery (CSRF) •