CVE-2023-1554: Quick Paypal Payments < 5.7.26.4 - Admin+ Stored XSS
The Quick Paypal Payments WordPress plugin before 5.7.26.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfilteredhtml capability is disallowed (for example in multisite setup)
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2023-1554.
What is the severity of CVE-2023-1554?
The severity of CVE-2023-1554 is medium with a score of 4.8.
What is the affected software?
The affected software is Quick Paypal Payments WordPress plugin version up to 5.7.26.4.
What is the description of CVE-2023-1554 vulnerability?
The Quick Paypal Payments WordPress plugin before 5.7.26.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
Is there a reference for CVE-2023-1554 vulnerability?
Yes, you can find more information about CVE-2023-1554 vulnerability at this [link](https://wpscan.com/vulnerability/0d247a3d-154e-4da7-a147-c1c7e1b5e87e).