CVE-2015-7666
Payment Form for PayPal Pro < 1.0.2 - Reflected Cross-Site Scripting
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Multiple cross-site scripting (XSS) vulnerabilities in the (1) cp_updateMessageItem and (2) cp_deleteMessageItem functions in cp_ppp_admin_int_message_list.inc.php in the Payment Form for PayPal Pro plugin before 1.0.2 for WordPress allow remote attackers to inject arbitrary web script or HTML via the cal parameter.
Múltiples vulnerabilidades de Cross-Site Scripting (XSS) en las funciones (1) cp_updateMessageItem y (2) cp_deleteMessageItem en cp_ppp_admin_int_message_list.inc.php en el plugin Payment Form for PayPal Pro, en versiones anteriores a la 1.0.2 para WordPress, permite que atacantes remotos inyecten scripts web o HTML arbitrarios mediante el parámetro cal.
WordPress DWBooster Payment Form for PayPal Pro plugin version 1.0.1 suffers from a cross site scripting vulnerability.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2015-10-01 CVE Reserved
- 2015-10-04 CVE Published
- 2023-05-20 EPSS Updated
- 2024-08-06 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
References (4)
URL | Tag | Source |
---|---|---|
http://www.securityfocus.com/archive/1/536602/100/0/threaded | Mailing List | |
https://plugins.trac.wordpress.org/changeset/1254452/payment-form-for-paypal-pro | Third Party Advisory | |
https://wordpress.org/plugins/payment-form-for-paypal-pro/#developers | Release Notes |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://wpvulndb.com/vulnerabilities/8210 | 2019-07-26 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Codepeople Search vendor "Codepeople" | Payment Form For Paypal Pro Search vendor "Codepeople" for product "Payment Form For Paypal Pro" | <= 1.0.1 Search vendor "Codepeople" for product "Payment Form For Paypal Pro" and version " <= 1.0.1" | wordpress |
Affected
|