plugin

Easy Paypal Donation Vulnerabilities

19 known security issues reported for the Easy Paypal Donation WordPress plugin. Most recent disclosed Jul 23, 2026.

1 high 8 medium

Running Easy Paypal Donation on your site? Check whether your installed version is affected.

Scan your site free

Accept Donations with PayPal & Stripe <= 1.5.5 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Accept Donations with PayPal & Stripe plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.5.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary...

CVSS:
6.4
Affected:
up to 1.5.5
Fixed in:
1.5.6
Disclosed:
Jul 23, 2026

CVE-2026-65518 on NVD →

Accept Donations with PayPal <= 1.5.2 - Unauthenticated Open Redirect

medium

The Accept Donations with PayPal & Stripe plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 1.5.2. This is due to insufficient validation on the redirect url supplied. This makes it possible for unauthenticated attackers to redirect users to potentially malicious sites if they ca...

CVSS:
4.7
Affected:
up to 1.5.2
Fixed in:
1.5.3
Disclosed:
Dec 25, 2025

CVE-2025-68602 on NVD →

Accept Donations with PayPal &amp; Stripe [easy-paypal-donation] <= 1.5.1 (unfixed)

unknown

[en] URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Scott Paterson Accept Donations with PayPal easy-paypal-donation allows Phishing.This issue affects Accept Donations with PayPal: from n/a through <= 1.5.1.

Affected:
up to 1.5.1
Fix:
No patched version reported
Disclosed:
Dec 24, 2025

CVE-2025-68602 on NVD →

Accept Donations with PayPal <= 1.4.5 - Cross-Site Request Forgery to Stored Cross-Site Scripting

medium

The Accept Donations with PayPal & Stripe plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.4.5. This is due to missing or incorrect nonce validation on the render() function. This makes it possible for unauthenticated attackers to update settings and inject malici...

CVSS:
6.1
Affected:
up to 1.4.5
Fixed in:
1.5
Disclosed:
May 7, 2025

CVE-2025-47517 on NVD →

Accept Donations with PayPal &amp; Stripe [easy-paypal-donation] < 1.5

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in Scott Paterson Accept Donations with PayPal allows Stored XSS. This issue affects Accept Donations with PayPal: from n/a through 1.4.5.

Affected:
up to 1.5
Fixed in:
1.5
Disclosed:
May 7, 2025

CVE-2025-47517 on NVD →

Accept Donations with PayPal &amp; Stripe [easy-paypal-donation] < 1.4.5

unknown

[en] The Accept Donations with PayPal & Stripe plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the rf parameter in all versions up to, and including, 1.4.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web sc...

Affected:
up to 1.4.5
Fixed in:
1.4.5
Disclosed:
Feb 23, 2025

CVE-2024-13728 on NVD →

Accept Donations with PayPal & Stripe <= 1.4.4 - Reflected Cross-Site Scripting

medium

The Accept Donations with PayPal & Stripe plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the rf parameter in all versions up to, and including, 1.4.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts...

CVSS:
6.1
Affected:
up to 1.4.4
Fixed in:
1.4.5
Disclosed:
Feb 22, 2025

CVE-2024-13728 on NVD →

Accept Donations with PayPal <= 1.3 - Reflected Cross-Site Scripting via Page

medium

The Accept Donations with PayPal plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘page’ parameter in versions up to, and including, 1.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages t...

CVSS:
6.1
Affected:
up to 1.3
Fixed in:
1.3.1
Disclosed:
May 25, 2022

Accept Donations with PayPal &amp; Stripe [easy-paypal-donation] < 1.3.1

unknown

The Accept Donations with PayPal plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘page’ parameter in versions up to, and including, 1.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages t...

Affected:
up to 1.3.1
Fixed in:
1.3.1
Disclosed:
May 25, 2022

Accept Donations with PayPal &amp; Stripe [easy-paypal-donation] < 1.3.4

unknown

[en] The Accept Donations with PayPal WordPress plugin before 1.3.4 does not have CSRF check in place and does not ensure that the post to be deleted belongs to the plugin, allowing attackers to make a logged in admin delete arbitrary posts from the blog

Affected:
up to 1.3.4
Fixed in:
1.3.4
Disclosed:
Jan 24, 2022

CVE-2021-24989 on NVD →

Accept Donations with PayPal <= 1.3.3 - Arbitrary Post Deletion via Cross-Site Request Forgery

medium

The Accept Donations with PayPal WordPress plugin before 1.3.4 does not have CSRF check in place and does not ensure that the post to be deleted belongs to the plugin, allowing attackers to make a logged in admin delete arbitrary posts from the blog

CVSS:
6.5
Affected:
up to 1.3.3
Fixed in:
1.3.4
Disclosed:
Dec 9, 2021

CVE-2021-24989 on NVD →

Accept Donations with PayPal &amp; Stripe [easy-paypal-donation] < 1.3.2

unknown

[en] The Accept Donations with PayPal WordPress plugin before 1.3.2 does not escape the Amount Menu Name field of created Buttons, which could allow a high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

Affected:
up to 1.3.2
Fixed in:
1.3.2
Disclosed:
Nov 17, 2021

CVE-2021-24815 on NVD →

Accept Donations with PayPal &amp; Stripe [easy-paypal-donation] < 1.3.2

unknown

[en] The Accept Donations with PayPal WordPress plugin before 1.3.1 offers a function to create donation buttons, which internally are posts. The process to create a new button is lacking a CSRF check. An attacker could use this to make an authenticated admin create a new button. Furthermore, one of the Button field is...

Affected:
up to 1.3.2
Fixed in:
1.3.2
Disclosed:
Nov 1, 2021

CVE-2021-24570 on NVD →

Accept Donations with PayPal &amp; Stripe [easy-paypal-donation] < 1.3.2

unknown

[en] The Accept Donations with PayPal WordPress plugin before 1.3.1 provides a function to create donation buttons which are internally stored as posts. The deletion of a button is not CSRF protected and there is no control to check if the deleted post was a button post. As a result, an attacker could make logged in ad...

Affected:
up to 1.3.2
Fixed in:
1.3.2
Disclosed:
Nov 1, 2021

CVE-2021-24572 on NVD →

Paypal Donation <= 1.3.1 - Admin+ Stored Cross-Site Scripting

medium

The Accept Donations with PayPal WordPress plugin before 1.3.2 does not escape the Amount Menu Name field of created Buttons, which could allow a high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

CVSS:
4.8
Affected:
up to 1.3.1
Fixed in:
1.3.2
Disclosed:
Oct 18, 2021

CVE-2021-24815 on NVD →

Accept Donations with PayPal &amp; Stripe [easy-paypal-donation] < 1.3.1

unknown

Reflected Cross-Site Scripting (XSS) vulnerability discovered by WPScanTeam in WordPress Accept Donations with PayPal plugin (versions <= 1.3).

Affected:
up to 1.3.1
Fixed in:
1.3.1
Disclosed:
Oct 11, 2021

Accept Donations with PayPal <= 1.3.0 Cross-Site Request Forgery to Post Deletion

high

The Accept Donations with PayPal WordPress plugin before 1.3.1 provides a function to create donation buttons which are internally stored as posts. The deletion of a button is not CSRF protected and there is no control to check if the deleted post was a button post. As a result, an attacker could make logged in admins...

CVSS:
8.8
Affected:
up to 1.3.1
Fixed in:
1.3.1
Disclosed:
Oct 4, 2021

CVE-2021-24572 on NVD →

Paypal Donation <= 1.3 - Cross-Site Request Forgery to Stored Cross-Site Scripting

medium

The Accept Donations with PayPal WordPress plugin before 1.3.1 offers a function to create donation buttons, which internally are posts. The process to create a new button is lacking a CSRF check. An attacker could use this to make an authenticated admin create a new button. Furthermore, one of the Button field is not...

CVSS:
6.1
Affected:
up to 1.3
Fixed in:
1.3.1
Disclosed:
Oct 4, 2021

CVE-2021-24570 on NVD →

Accept Donations with PayPal &amp; Stripe [easy-paypal-donation] < 1.3.1

unknown

The plugins do not escape a page parameter before outputting it back in an attribute in various admin pages, leading to Reflected Cross-Site Scripting issues. The issues were reported to the vendor on August 10th, 2021

Affected:
up to 1.3.1
Fixed in:
1.3.1

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database