CVE-2025-22640: WordPress Paytm Payment Donation Plugin <= 2.3.3 - Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in integrationdevpaytm Paytm Payment Donation paytm-donation allows Stored XSS.This issue affects Paytm Payment Donation: from n/a through <= 2.3.3.
Other sources
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Paytm Paytm Payment Donation allows Stored XSS.This issue affects Paytm Payment Donation: from n/a through 2.3.3.
— NVD
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-22640?
CVE-2025-22640 is classified as a medium severity vulnerability due to its potential for stored cross-site scripting attacks.
How do I fix CVE-2025-22640?
To fix CVE-2025-22640, you should update the Paytm Payment Donation plugin to the latest version beyond 2.3.3.
Which versions are affected by CVE-2025-22640?
CVE-2025-22640 affects all versions of Paytm Payment Donation up to and including 2.3.3.
What kind of attack does CVE-2025-22640 allow?
CVE-2025-22640 allows stored cross-site scripting (XSS), which can lead to malicious script execution in users' browsers.
Who is impacted by CVE-2025-22640?
Users of the Paytm Payment Donation plugin for WordPress who are running versions up to 2.3.3 are impacted by CVE-2025-22640.