Wpplugin

Accept Donations With Paypal

5 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.01%
  • Published 07.05.2025 14:20:05
  • Last modified 09.06.2025 16:56:44

Cross-Site Request Forgery (CSRF) vulnerability in Scott Paterson Accept Donations with PayPal allows Stored XSS. This issue affects Accept Donations with PayPal: from n/a through 1.4.5.

Exploit
  • EPSS 0.1%
  • Published 24.01.2022 08:15:09
  • Last modified 21.11.2024 05:54:08

The Accept Donations with PayPal WordPress plugin before 1.3.4 does not have CSRF check in place and does not ensure that the post to be deleted belongs to the plugin, allowing attackers to make a logged in admin delete arbitrary posts from the blog

Exploit
  • EPSS 0.21%
  • Published 17.11.2021 11:15:08
  • Last modified 21.11.2024 05:53:49

The Accept Donations with PayPal WordPress plugin before 1.3.2 does not escape the Amount Menu Name field of created Buttons, which could allow a high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is...

Exploit
  • EPSS 0.16%
  • Published 01.11.2021 09:15:08
  • Last modified 21.11.2024 05:53:19

The Accept Donations with PayPal WordPress plugin before 1.3.1 offers a function to create donation buttons, which internally are posts. The process to create a new button is lacking a CSRF check. An attacker could use this to make an authenticated a...

Exploit
  • EPSS 0.14%
  • Published 01.11.2021 09:15:08
  • Last modified 21.11.2024 05:53:19

The Accept Donations with PayPal WordPress plugin before 1.3.1 provides a function to create donation buttons which are internally stored as posts. The deletion of a button is not CSRF protected and there is no control to check if the deleted post wa...