First published: Thu Apr 17 2025(Updated: )
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in codepeople Payment Form for PayPal Pro allows Stored XSS. This issue affects Payment Form for PayPal Pro: from n/a through 1.1.72.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
WordPress Payment Form for PayPal Pro | <=1.1.72 | |
WordPress Payment Form for PayPal Pro | <=1.1.72 |
Update the WordPress Payment Form for PayPal Pro plugin to the latest available version (at least 1.1.73).
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-39562 is a Stored XSS vulnerability, which can allow attackers to inject malicious scripts into web pages viewed by other users.
To mitigate CVE-2025-39562, update the Payment Form for PayPal Pro plugin to the latest version beyond 1.1.72.
CVE-2025-39562 affects the Payment Form for PayPal Pro plugin versions from n/a through 1.1.72.
CVE-2025-39562 is classified as a Cross-site Scripting (XSS) vulnerability due to improper neutralization of user inputs.
Yes, testing for CVE-2025-39562 can be done by attempting to inject scripts into the Payment Form for PayPal Pro input fields and observing whether they are executed.