CVE-2026-65517: WordPress Easy PayPal Buy Now Button plugin <= 2.0.4 - Cross Site Scripting (XSS) vulnerability
Unauthenticated Cross Site Scripting (XSS) in Easy PayPal Buy Now Button <= 2.0.4 versions.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Easy PayPal Buy Now Button pluginto a version that resolves this vulnerability.Fixed in 2.0.5
Event History
Frequently Asked Questions
What is the severity of CVE-2026-65517?
CVE-2026-65517 has a high severity rating of 7.1 due to its potential impact on site security.
How do I fix CVE-2026-65517?
To fix CVE-2026-65517, update the Easy PayPal Buy Now Button plugin to version 2.0.5 or later.
What type of vulnerability is CVE-2026-65517?
CVE-2026-65517 is classified as a Cross Site Scripting (XSS) vulnerability affecting the Easy PayPal Buy Now Button plugin.
Which versions are affected by CVE-2026-65517?
CVE-2026-65517 affects versions of the Easy PayPal Buy Now Button plugin up to and including 2.0.4.
Is CVE-2026-65517 an authenticated or unauthenticated vulnerability?
CVE-2026-65517 is an unauthenticated Cross Site Scripting (XSS) vulnerability, meaning it can be exploited without user authentication.