4 results (0.009 seconds)

CVSS: 6.5EPSS: 0%CPEs: 1EXPL: 1

09 Dec 2021 — The Accept Donations with PayPal WordPress plugin before 1.3.4 does not have CSRF check in place and does not ensure that the post to be deleted belongs to the plugin, allowing attackers to make a logged in admin delete arbitrary posts from the blog El plugin Accept Donations with PayPal de WordPress versiones anteriores a 1.3.4, no presenta una comprobación CSRF y no asegura de que la entrada que va a ser eliminada pertenece al plugin, permitiendo a atacantes hacer que un administrador conectado elimine en... • https://wpscan.com/vulnerability/82c2ead1-1d3c-442a-ae68-359a4748447f • CWE-352: Cross-Site Request Forgery (CSRF) •

CVSS: 4.8EPSS: 0%CPEs: 1EXPL: 1

18 Oct 2021 — The Accept Donations with PayPal WordPress plugin before 1.3.2 does not escape the Amount Menu Name field of created Buttons, which could allow a high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed. El plugin Accept Donations with PayPal de WordPress versiones anteriores a 1.3.2, no escapa del campo Amount Menu Name de los botones creados, que podría permitir a un usuario con altos privilegios llevar a cabo ataques de tipo Cross-Site Scripting ... • https://wpscan.com/vulnerability/08f4ebf5-6bbe-4fb0-a9d2-c8a994afe39b • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 8.8EPSS: 0%CPEs: 1EXPL: 1

04 Oct 2021 — The Accept Donations with PayPal WordPress plugin before 1.3.1 provides a function to create donation buttons which are internally stored as posts. The deletion of a button is not CSRF protected and there is no control to check if the deleted post was a button post. As a result, an attacker could make logged in admins delete arbitrary posts El plugin Accept Donations with PayPal de WordPress versiones anteriores a 1.3.1, proporciona una función para crear botones de donación que se almacenan internamente co... • https://wpscan.com/vulnerability/7b1ebd26-ea8b-448c-a775-66a04102e44f • CWE-352: Cross-Site Request Forgery (CSRF) •

CVSS: 6.1EPSS: 0%CPEs: 1EXPL: 1

04 Oct 2021 — The Accept Donations with PayPal WordPress plugin before 1.3.1 offers a function to create donation buttons, which internally are posts. The process to create a new button is lacking a CSRF check. An attacker could use this to make an authenticated admin create a new button. Furthermore, one of the Button field is not escaped before being output in an attribute when editing a Button, leading to a Stored Cross-Site Scripting issue as well. El plugin Accept Donations with PayPal de WordPress versiones anterio... • https://plugins.trac.wordpress.org/changeset/2608073 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CWE-352: Cross-Site Request Forgery (CSRF) •