First published: Wed Nov 17 2021(Updated: )
The Accept Donations with PayPal WordPress plugin before 1.3.2 does not escape the Amount Menu Name field of created Buttons, which could allow a high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
Accept Donations With Paypal | <1.3.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2021-24815.
The title of this vulnerability is 'The Accept Donations with PayPal WordPress plugin before 1.3.2 does not escape the Amount Menu Name field of created Buttons'.
The severity of CVE-2021-24815 is medium, with a severity value of 4.8.
The Accept Donations with PayPal WordPress plugin before version 1.3.2 is affected by CVE-2021-24815.
This vulnerability can be exploited by high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.