Medium severity6.1NVD Advisory· Published Dec 27, 2017· Updated Jun 17, 2026
CVE-2015-7666
CVE-2015-7666
Description
Multiple cross-site scripting (XSS) vulnerabilities in the (1) cp_updateMessageItem and (2) cp_deleteMessageItem functions in cp_ppp_admin_int_message_list.inc.php in the Payment Form for PayPal Pro plugin before 1.0.2 for WordPress allow remote attackers to inject arbitrary web script or HTML via the cal parameter.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3(expand)+ 1 more
- (no CPE)
- (no CPE)range: <1.0.2
- cpe:2.3:a:codepeople:payment_form_for_paypal_pro:*:*:*:*:*:wordpress:*:*Range: <=1.0.1
Patches
Vulnerability mechanics
References
4- www.securityfocus.com/archive/1/536602/100/0/threadednvdThird Party AdvisoryVDB Entry
- plugins.trac.wordpress.org/changeset/1254452/payment-form-for-paypal-pronvdThird Party Advisory
- wordpress.org/plugins/payment-form-for-paypal-pro/nvdRelease NotesThird Party Advisory
- wpvulndb.com/vulnerabilities/8210nvdThird Party AdvisoryVendor Advisory
News mentions
0No linked articles in our index yet.