VYPR

Payment Button for PayPal

by WordPress

CVEs (3)

  • CVE-2024-13401MedJan 17, 2025
    risk 0.42cvss 6.4epss 0.00

    The Payment Button for PayPal plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wp_paypal_checkout' shortcode in all versions up to, and including, 1.2.3.35 due to insufficient input sanitization and output escaping on user supplied attributes.…

  • CVE-2026-16990MedAug 12, 2026
    risk 0.34cvss 5.3epss 0.00

    The Payment Button for PayPal WordPress plugin through 1.2.3.44 does not enforce the merchant-configured price server-side and trusts a client-supplied payment amount, allowing unauthenticated attackers to create a real PayPal order against the merchant for an arbitrary lower…

  • CVE-2025-14463MedJan 17, 2026
    risk 0.34cvss 5.3epss 0.00

    The Payment Button for PayPal plugin for WordPress is vulnerable to unauthorized order creation in all versions up to, and including, 1.2.3.41. This is due to the plugin exposing a public AJAX endpoint (`wppaypalcheckout_ajax_process_order`) that processes checkout results…