CVE-2023-25702: WordPress Quick Paypal Payments Plugin <= 5.7.25 is vulnerable to Cross Site Scripting (XSS)
Auth. (admin+) Stored Cross-site Scripting (XSS) vulnerability in Fullworks Quick Paypal Payments plugin <= 5.7.25 versions.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2023-25702?
CVE-2023-25702 is an authentication bypass vulnerability that allows an attacker with administrative privileges to execute stored cross-site scripting (XSS) attacks on the Fullworks Quick Paypal Payments plugin version 5.7.25 and below for WordPress.
How does CVE-2023-25702 impact Fullworks Quick Paypal Payments plugin?
CVE-2023-25702 allows an attacker with administrative access to inject malicious scripts into the plugin, which can be executed when users interact with the affected pages.
What is the severity of CVE-2023-25702?
CVE-2023-25702 has a severity rating of 4.8 (medium).
How can I fix CVE-2023-25702?
To fix CVE-2023-25702, it is recommended to update the Fullworks Quick Paypal Payments plugin to version 5.7.26 or newer, which contains a patch for this vulnerability.
What is the CWE category of CVE-2023-25702?
CVE-2023-25702 belongs to the CWE category 79 (Cross-Site Scripting).