The Easy PayPal Buy Now Button WordPress plugin before 1.7.4 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks
2023-02-13T15:15:18.343
2025-03-21T15:15:39.010
Modified
CVSSv3.1: 5.4 (MEDIUM)
-
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | wpplugin | easy_paypal_buy_now_button | < 1.7.4 | Yes |