plugin

Quick Paypal Payments Vulnerabilities

29 known security issues reported for the Quick Paypal Payments WordPress plugin. Most recent disclosed Aug 5, 2026.

2 high 7 medium

Running Quick Paypal Payments on your site? Check whether your installed version is affected.

Scan your site free

Quick Paypal Payments <= 5.7.50 - Unauthenticated Payment Bypass

medium

The Quick Paypal Payments plugin for WordPress is vulnerable to Payment Bypass in all versions up to, and including, 5.7.50. This makes it possible for unauthenticated attackers to bypass payments.

CVSS:
5.3
Affected:
up to 5.7.50
Fix:
No patched version reported
Disclosed:
Aug 5, 2026

CVE-2026-17008 on NVD →

Quick Paypal Payments [quick-paypal-payments] < 5.7.47

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in fullworks Quick Paypal Payments allows Cross Site Request Forgery. This issue affects Quick Paypal Payments: from n/a through 5.7.46.

Affected:
up to 5.7.47
Fixed in:
5.7.47
Disclosed:
Sep 5, 2025

CVE-2025-27003 on NVD →

Quick Paypal Payments <= 5.7.46 - Cross-Site Request Forgery

medium

The Quick Paypal Payments plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5.7.46. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to perform an unauthorized action granted they can trick a sit...

CVSS:
4.3
Affected:
up to 5.7.46
Fixed in:
5.7.47
Disclosed:
Sep 4, 2025

CVE-2025-27003 on NVD →

Quick Paypal Payments [quick-paypal-payments] < 5.7.26 (closed)

unknown

[en] Missing Authorization vulnerability in Fullworks Quick Paypal Payments allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Quick Paypal Payments: from n/a through 5.7.25.

Affected:
up to 5.7.26
Fixed in:
5.7.26
Disclosed:
Dec 9, 2024

CVE-2023-25714 on NVD →

Quick Paypal Payments [quick-paypal-payments] < 5.7.22 (closed)

unknown

[en] The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions in versions up to, and including 2.4....

Affected:
up to 5.7.22
Fixed in:
5.7.22
Disclosed:
Oct 16, 2024

CVE-2022-4974 on NVD →

Quick Paypal Payments [quick-paypal-payments] < 3.1 (closed)

unknown

This plugin is not fixed. An unknown person discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Quick Paypal Payments Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed...

Affected:
up to 3.1
Fixed in:
3.1
Disclosed:
May 15, 2023

Quick Paypal Payments [quick-paypal-payments] < 5.7.26.4 (closed)

unknown

[en] The Quick Paypal Payments WordPress plugin before 5.7.26.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

Affected:
up to 5.7.26.4
Fixed in:
5.7.26.4
Disclosed:
May 2, 2023

CVE-2023-1554 on NVD →

Quick Paypal Payments [quick-paypal-payments] < 5.7.26 (closed)

unknown

[en] Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Fullworks Quick Paypal Payments plugin <= 5.7.25 versions.

Affected:
up to 5.7.26
Fixed in:
5.7.26
Disclosed:
Apr 25, 2023

CVE-2023-23889 on NVD →

Quick Paypal Payments [quick-paypal-payments] < 5.7.26 (closed)

unknown

[en] Unauth. Stored Cross-Site Scripting (XSS) vulnerability in Fullworks Quick Paypal Payments plugin <= 5.7.25 versions.

Affected:
up to 5.7.26
Fixed in:
5.7.26
Disclosed:
Apr 7, 2023

CVE-2023-25713 on NVD →

Quick Paypal Payments [quick-paypal-payments] < 5.7.26 (closed)

unknown

[en] Auth. (admin+) Stored Cross-site Scripting (XSS) vulnerability in Fullworks Quick Paypal Payments plugin <= 5.7.25 versions.

Affected:
up to 5.7.26
Fixed in:
5.7.26
Disclosed:
Apr 7, 2023

CVE-2023-25702 on NVD →

Quick Paypal Payments [quick-paypal-payments] < 5.7.26.4 (closed)

unknown

Update the WordPress Quick Paypal Payments plugin to the latest available version (at least 5.7.26.4). Unknown discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Quick Paypal Payments Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisement...

Affected:
up to 5.7.26.4
Fixed in:
5.7.26.4
Disclosed:
Mar 29, 2023

Quick Paypal Payments <= 5.7.26.3 - Authenticated (Administrator+) Stored Cross-Site Scripting

medium

The Quick Paypal Payments for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 5.7.26.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arb...

CVSS:
4.4
Affected:
up to 5.7.26.3
Fixed in:
5.7.26.4
Disclosed:
Mar 27, 2023

CVE-2023-1554 on NVD →

Quick Paypal Payments [quick-paypal-payments] < 5.7.26.4 (closed)

unknown

The Quick Paypal Payments for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 5.7.26.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arb...

Affected:
up to 5.7.26.4
Fixed in:
5.7.26.4
Disclosed:
Mar 27, 2023

Quick Paypal Payments [quick-paypal-payments] < 5.7.22 (closed)

unknown

Update the WordPress Quick Paypal Payments plugin to the latest available version (at least 5.7.22). An unknown person discovered and reported this Sensitive Data Exposure vulnerability in WordPress Quick Paypal Payments Plugin. This vulnerability has been fixed in version 5.7.22.

Affected:
up to 5.7.22
Fixed in:
5.7.22
Disclosed:
Feb 28, 2023

Quick Paypal Payments [quick-paypal-payments] < 5.7.22 (closed)

unknown

Update the WordPress Quick Paypal Payments plugin to the latest available version (at least 5.7.22). An unknown person discovered and reported this Cross Site Request Forgery (CSRF) vulnerability in WordPress Quick Paypal Payments Plugin. This could allow a malicious actor to force higher privileged users to execute un...

Affected:
up to 5.7.22
Fixed in:
5.7.22
Disclosed:
Feb 28, 2023

Quick Paypal Payments <= 5.7.25 - Authenticated (Contributor+) Cross Site Scripting

medium

The Quick Paypal Payments plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in versions up to, and including, 5.7.25 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor l...

CVSS:
6.4
Affected:
up to 5.7.25
Fixed in:
5.7.26
Disclosed:
Feb 15, 2023

CVE-2023-23889 on NVD →

Quick Paypal Payments <= 5.7.25 - Missing Authorization

high

The Quick Paypal Payments plugin for WordPress is vulnerable to unauthorized access and modification of data due to a missing capability and nonce check on the 'download_logs' function in versions up to, and including, 5.7.25. This allows unauthenticated attackers to export and delete payment messages and modify paymen...

CVSS:
7.3
Affected:
up to 5.7.25
Fixed in:
5.7.26
Disclosed:
Feb 14, 2023

CVE-2023-25714 on NVD →

Quick Paypal Payments <= 5.7.25 - Unauthenticated Stored Cross Site Scripting

high

The Quick Paypal Payments plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 5.7.25 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user...

CVSS:
7.2
Affected:
up to 5.7.26
Fixed in:
5.7.26
Disclosed:
Feb 14, 2023

CVE-2023-25713 on NVD →

Quick Paypal Payments <= 5.7.25 - Authenticated (Administrator+) Stored Cross-Site Scripting

medium

The Quick Paypal Payments plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings through several parameters (blurb, comboboxword, comboboxlabel, shortcodeamount, postagepercent, postagefixed, couponref, couponbutton, minamount, recurringhowmany, Dperiod, Wperiod, Mperiod, Yperiod, every, q...

CVSS:
5.5
Affected:
up to 5.7.25
Fixed in:
5.7.26
Disclosed:
Feb 10, 2023

CVE-2023-25702 on NVD →

Quick Paypal Payments [quick-paypal-payments] < 5.7.26 (closed)

unknown

The Quick Paypal Payments plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings through several parameters (blurb, comboboxword, comboboxlabel, shortcodeamount, postagepercent, postagefixed, couponref, couponbutton, minamount, recurringhowmany, Dperiod, Wperiod, Mperiod, Yperiod, every, q...

Affected:
up to 5.7.26
Fixed in:
5.7.26
Disclosed:
Feb 10, 2023

Freemius SDK <= 2.4.2 - Missing Authorization Checks

medium

The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions in versions up to, and including 2.4.2. An...

CVSS:
6.3
Affected:
up to 5.7.22
Fixed in:
5.7.22
Disclosed:
Mar 4, 2022

CVE-2022-4974 on NVD →

Quick Paypal Payments [quick-paypal-payments] < 5.7.22 (closed)

unknown

The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions in versions up to, and including 2.4.2. An...

Affected:
up to 5.7.22
Fixed in:
5.7.22
Disclosed:
Mar 4, 2022

Quick Paypal Payments [quick-paypal-payments] < 5.7.22 (closed)

unknown

Sensitive Information Disclosure vulnerability discovered in WordPress Quick Paypal Payments plugin (versions < 5.7.22).

Affected:
up to 5.7.22
Fixed in:
5.7.22
Disclosed:
Feb 28, 2022

Quick Paypal Payments [quick-paypal-payments] < 5.7.22 (closed)

unknown

Sensitive Information Disclosure vulnerability discovered in WordPress Quick Paypal Payments plugin (versions < 5.7.22).

Affected:
up to 5.7.22
Fixed in:
5.7.22
Disclosed:
Feb 28, 2022

Quick Paypal Payments [quick-paypal-payments] < 3.1 (closed)

unknown

Because of this vulnerability, the attackers can inject arbitrary JavaScript or HTML code. This plugin is not fixed.

Affected:
up to 3.1
Fixed in:
3.1
Disclosed:
May 15, 2015

Quick Paypal Payments < 3.1 - Cross-Site Scripting

medium

The Quick Paypal Payments plugin for WordPress is vulnerable to Cross-Site Scripting via the 'reference' and 'amount' parameters in versions before 3.1 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser.

CVSS:
6.1
Affected:
up to 3.1
Fixed in:
3.1
Disclosed:
Oct 18, 2013

Quick Paypal Payments [quick-paypal-payments] < 3.1 (closed)

unknown

The Quick Paypal Payments plugin for WordPress is vulnerable to Cross-Site Scripting via the 'reference' and 'amount' parameters in versions before 3.1 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser.

Affected:
up to 3.1
Fixed in:
3.1
Disclosed:
Oct 18, 2013

Quick Paypal Payments [quick-paypal-payments] < 5.7.29 (closed)

unknown

** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.

Affected:
up to 5.7.29
Fixed in:
5.7.29

CVE-2023-33999 on NVD →

Quick Paypal Payments [quick-paypal-payments] < 3.1 (closed)

unknown

The Quick Paypal Payments WordPress plugin was affected by a Payment Sending Multiple Parameter XSS security vulnerability.

Affected:
up to 3.1
Fixed in:
3.1

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database