First published: Wed May 07 2025(Updated: )
Cross-Site Request Forgery (CSRF) vulnerability in Scott Paterson Accept Donations with PayPal allows Stored XSS. This issue affects Accept Donations with PayPal: from n/a through 1.4.5.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Scott Paterson Accept Donations with PayPal | <=1.4.5 | |
WordPress Accept Donations with PayPal plugin | <=1.4.5 |
Update the WordPress Accept Donations with PayPal plugin to the latest available version (at least 1.5).
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-47517 is classified as a medium severity vulnerability due to its potential for exploitation through Cross-Site Request Forgery leading to Stored XSS.
To fix CVE-2025-47517, update the Accept Donations with PayPal plugin to version 1.4.6 or later.
CVE-2025-47517 affects versions of Accept Donations with PayPal from release through 1.4.5.
CVE-2025-47517 is a Cross-Site Request Forgery (CSRF) vulnerability that allows for Stored XSS.
Anyone using Scott Paterson's Accept Donations with PayPal plugin version 1.4.5 or earlier on their WordPress site is impacted by CVE-2025-47517.