CVE-2025-68602: WordPress Accept Donations with PayPal plugin <= 1.5.2 - Open Redirection vulnerability
Published Dec 24, 2025
·Updated
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Scott Paterson Accept Donations with PayPal & Stripe easy-paypal-donation allows Phishing.This issue affects Accept Donations with PayPal & Stripe: from n/a through <= 1.5.2.
Affected Software
1 affected component
Scott Paterson Accept Donations with PayPal & Stripe<=1.5.2
Event History
Dec 24, 2025
CVE Published
via MITRE·01:10 PM
Data Sourced
via MITRE·01:10 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·01:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-68602?
The severity of CVE-2025-68602 is considered medium due to its potential for phishing attacks.
2
How do I fix CVE-2025-68602?
To fix CVE-2025-68602, update the Accept Donations with PayPal plugin to version 1.5.2 or later.
3
What types of attacks can CVE-2025-68602 facilitate?
CVE-2025-68602 can facilitate phishing attacks by redirecting users to untrusted sites.
4
Which versions are affected by CVE-2025-68602?
CVE-2025-68602 affects Accept Donations with PayPal versions up to and including 1.5.1.
5
Who is affected by CVE-2025-68602?
Users of the Accept Donations with PayPal plugin for WordPress, specifically versions 1.5.1 and earlier, are affected by CVE-2025-68602.