Wpplugin Accept Donations With Paypal vulnerabilities
5 known vulnerabilities affecting wpplugin/accept_donations_with_paypal.
Total CVEs
5
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
MEDIUM5
Vulnerabilities
Page 1 of 1
CVE-2025-47517MEDIUMCVSS 6.1fixed in 1.52025-05-07
CVE-2025-47517 [MEDIUM] CWE-352 CVE-2025-47517: Cross-Site Request Forgery (CSRF) vulnerability in Scott Paterson Accept Donations with PayPal & Str
Cross-Site Request Forgery (CSRF) vulnerability in Scott Paterson Accept Donations with PayPal & Stripe easy-paypal-donation allows Stored XSS.This issue affects Accept Donations with PayPal & Stripe: from n/a through <= 1.4.5.
nvd
CVE-2021-24989MEDIUMCVSS 6.5fixed in 1.3.42022-01-24
CVE-2021-24989 [MEDIUM] CWE-352 CVE-2021-24989: The Accept Donations with PayPal WordPress plugin before 1.3.4 does not have CSRF check in place and
The Accept Donations with PayPal WordPress plugin before 1.3.4 does not have CSRF check in place and does not ensure that the post to be deleted belongs to the plugin, allowing attackers to make a logged in admin delete arbitrary posts from the blog
nvd
CVE-2021-24815MEDIUMCVSS 4.8fixed in 1.3.22021-11-17
CVE-2021-24815 [MEDIUM] CWE-79 CVE-2021-24815: The Accept Donations with PayPal WordPress plugin before 1.3.2 does not escape the Amount Menu Name
The Accept Donations with PayPal WordPress plugin before 1.3.2 does not escape the Amount Menu Name field of created Buttons, which could allow a high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.
nvd
CVE-2021-24572MEDIUMCVSS 4.3fixed in 1.3.12021-11-01
CVE-2021-24572 [MEDIUM] CWE-352 CVE-2021-24572: The Accept Donations with PayPal WordPress plugin before 1.3.1 provides a function to create donatio
The Accept Donations with PayPal WordPress plugin before 1.3.1 provides a function to create donation buttons which are internally stored as posts. The deletion of a button is not CSRF protected and there is no control to check if the deleted post was a button post. As a result, an attacker could make logged in admins delete arbitrary posts
nvd
CVE-2021-24570MEDIUMCVSS 4.3fixed in 1.3.12021-11-01
CVE-2021-24570 [MEDIUM] CWE-79 CVE-2021-24570: The Accept Donations with PayPal WordPress plugin before 1.3.1 offers a function to create donation
The Accept Donations with PayPal WordPress plugin before 1.3.1 offers a function to create donation buttons, which internally are posts. The process to create a new button is lacking a CSRF check. An attacker could use this to make an authenticated admin create a new button. Furthermore, one of the Button field is not escaped before being output in an
nvd