First published: Wed May 07 2025(Updated: )
Cross-Site Request Forgery (CSRF) vulnerability in Scott Paterson Easy PayPal Events allows Cross Site Request Forgery. This issue affects Easy PayPal Events: from n/a through 1.2.2.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Scott Paterson Easy PayPal Events | <=1.2.2 | |
WordPress Easy PayPal Events | <=1.2.2 |
Update the WordPress Easy PayPal Events plugin to the latest available version (at least 1.3).
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-47519 is classified as a Cross-Site Request Forgery (CSRF) vulnerability with critical implications for user security.
To fix CVE-2025-47519, update the Easy PayPal Events plugin to version 1.2.3 or later.
CVE-2025-47519 is caused by insufficient validation of HTTP requests, allowing unauthorized actions to be performed on behalf of logged-in users.
CVE-2025-47519 affects Easy PayPal Events versions up to and including 1.2.2.
Users and site administrators using affected versions of Scott Paterson's Easy PayPal Events plugin are at risk due to CVE-2025-47519.