CVE-2025-47623: WordPress Easy PayPal Buy Now Button plugin <= 2.0 - Cross Site Scripting (XSS) Vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Scott Paterson Easy PayPal Buy Now Button wp-ecommerce-paypal allows Stored XSS.This issue affects Easy PayPal Buy Now Button: from n/a through <= 2.0.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-47623?
CVE-2025-47623 has been classified as a high severity vulnerability due to its potential for stored cross-site scripting (XSS) attacks.
How do I fix CVE-2025-47623?
To fix CVE-2025-47623, you should update the Easy PayPal Buy Now Button plugin to version 2.1 or later.
What type of vulnerability is CVE-2025-47623?
CVE-2025-47623 is an improper neutralization of input during web page generation, specifically a cross-site scripting (XSS) vulnerability.
Who is affected by CVE-2025-47623?
CVE-2025-47623 affects users of the Easy PayPal Buy Now Button plugin, specifically versions up to and including 2.0.
What can attackers do with CVE-2025-47623?
Attackers exploiting CVE-2025-47623 can execute arbitrary JavaScript code in the context of the victim's browser, potentially leading to data theft or session hijacking.