CVE-2025-39562: WordPress Payment Form for PayPal Pro plugin <= 1.1.72 - Cross Site Scripting (XSS) Vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in codepeople Payment Form for PayPal Pro payment-form-for-paypal-pro allows Stored XSS.This issue affects Payment Form for PayPal Pro: from n/a through <= 1.1.72.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-39562?
CVE-2025-39562 is a Stored XSS vulnerability, which can allow attackers to inject malicious scripts into web pages viewed by other users.
How do I fix CVE-2025-39562?
To mitigate CVE-2025-39562, update the Payment Form for PayPal Pro plugin to the latest version beyond 1.1.72.
What versions are affected by CVE-2025-39562?
CVE-2025-39562 affects the Payment Form for PayPal Pro plugin versions from n/a through 1.1.72.
What type of vulnerability is CVE-2025-39562?
CVE-2025-39562 is classified as a Cross-site Scripting (XSS) vulnerability due to improper neutralization of user inputs.
Can I test for CVE-2025-39562 in my application?
Yes, testing for CVE-2025-39562 can be done by attempting to inject scripts into the Payment Form for PayPal Pro input fields and observing whether they are executed.