plugin

Wp Ecommerce Paypal Vulnerabilities

15 known security issues reported for the Wp Ecommerce Paypal WordPress plugin. Most recent disclosed Jul 28, 2026.

2 high 5 medium

Running Wp Ecommerce Paypal on your site? Check whether your installed version is affected.

Scan your site free

Easy PayPal & Stripe Buy Now Button <= 2.0.4 - Unauthenticated Stored Cross-Site Scripting

high

The Easy PayPal & Stripe Buy Now Button plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.0.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute wh...

CVSS:
7.2
Affected:
up to 2.0.4
Fixed in:
2.0.5
Disclosed:
Jul 28, 2026

CVE-2026-65517 on NVD →

Easy PayPal Buy Now Button <= 2.0 - Authenticated (Administrator+) Stored Cross-Site Scripting

medium

The Easy PayPal Buy Now Button plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access and above, to inject arbitrary web script...

CVSS:
4.4
Affected:
up to 2.0
Fixed in:
2.0.1
Disclosed:
May 7, 2025

CVE-2025-47623 on NVD →

Easy PayPal &amp; Stripe Buy Now Button [wp-ecommerce-paypal] <= 2.0 (unfixed)

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Scott Paterson Easy PayPal Buy Now Button allows Stored XSS. This issue affects Easy PayPal Buy Now Button: from n/a through 2.0.

Affected:
up to 2.0
Fix:
No patched version reported
Disclosed:
May 7, 2025

CVE-2025-47623 on NVD →

Easy PayPal &amp; Stripe Buy Now Button [wp-ecommerce-paypal] < 1.9.1

unknown

[en] URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Scott Paterson Easy PayPal Buy Now Button.This issue affects Easy PayPal Buy Now Button: from n/a through 1.9.

Affected:
up to 1.9.1
Fixed in:
1.9.1
Disclosed:
Aug 19, 2024

CVE-2024-43236 on NVD →

Easy PayPal Buy Now Button <= 1.9 - Unauthenticated Open Redirect

high

The Easy PayPal & Stripe Buy Now Button plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 1.9. This is due to insufficient validation on the redirect url supplied via the 'rf' parameter. This makes it possible for unauthenticated attackers to redirect users to potentially malicio...

CVSS:
7.2
Affected:
up to 1.9
Fixed in:
1.9.1
Disclosed:
Aug 9, 2024

CVE-2024-43236 on NVD →

Easy PayPal &amp; Stripe Buy Now Button [wp-ecommerce-paypal] < 1.8.2

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in Scott Paterson Easy PayPal & Stripe Buy Now Button.This issue affects Easy PayPal & Stripe Buy Now Button: from n/a through 1.8.1.

Affected:
up to 1.8.2
Fixed in:
1.8.2
Disclosed:
Feb 28, 2024

CVE-2023-51683 on NVD →

Easy PayPal &amp; Stripe Buy Now Button [wp-ecommerce-paypal] < 1.9

unknown

[en] The Easy PayPal & Stripe Buy Now Button plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.8.3 and in Contact Form 7 – PayPal & Stripe Add-on all versions up to, and including 2.1. This is due to missing or incorrect nonce validation on the 'wpecpp_stripe_conne...

Affected:
up to 1.9
Fixed in:
1.9
Disclosed:
Feb 28, 2024

CVE-2024-1719 on NVD →

Easy PayPal & Stripe Buy Now Button <= 1.8.3 & Contact Form 7 – PayPal & Stripe Add-on <= 2.1 - Cross-Site Request Forgery to Settings Update

medium

The Easy PayPal & Stripe Buy Now Button plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.8.3 and in Contact Form 7 – PayPal & Stripe Add-on all versions up to, and including 2.1. This is due to missing or incorrect nonce validation on the 'wpecpp_stripe_connect_co...

CVSS:
4.3
Affected:
up to 1.8.3
Fixed in:
1.9
Disclosed:
Feb 27, 2024

CVE-2024-1719 on NVD →

Easy PayPal Buy Now Button <= 1.8.1 - Cross-Site Request Forgery

medium

The Easy PayPal Buy Now Button plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.8.1. This is due to missing or incorrect nonce validation on one of its functions. This makes it possible for unauthenticated attackers to invoke this function via a forged request granted...

CVSS:
4.3
Affected:
up to 1.8.1
Fixed in:
1.8.2
Disclosed:
Dec 27, 2023

CVE-2023-51683 on NVD →

Easy PayPal &amp; Stripe Buy Now Button [wp-ecommerce-paypal] < 1.7.4

unknown

[en] The Easy PayPal Buy Now Button WordPress plugin before 1.7.4 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

Affected:
up to 1.7.4
Fixed in:
1.7.4
Disclosed:
Feb 13, 2023

CVE-2022-4628 on NVD →

Easy PayPal Buy Now Button <= 1.7.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

medium

The Easy PayPal Buy Now Button plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in versions up to, and including, 1.7.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor...

CVSS:
6.4
Affected:
up to 1.7.3
Fixed in:
1.7.4
Disclosed:
Jan 19, 2023

CVE-2022-4628 on NVD →

Easy PayPal &amp; Stripe Buy Now Button [wp-ecommerce-paypal] < 1.7.3

unknown

Update the WordPress Easy PayPal Buy Now Button plugin to the latest available version (at least 1.7.3). WPScanTeam discovered and reported this Cross Site Request Forgery (CSRF) vulnerability in WordPress Easy PayPal Buy Now Button Plugin. This could allow a malicious actor to force higher privileged users to execute...

Affected:
up to 1.7.3
Fixed in:
1.7.3
Disclosed:
Jan 19, 2023

Easy PayPal Buy Now Button <= 1.7.2 - Cross-Site Request Forgery to Cross-Site Scripting

medium

The Easy PayPal Buy Now Button plugin for WordPress is vulnerable to Cross-Site Request Forgery to Cross-Site Scripting in versions up to, and including, 1.7.2. This is due to missing or incorrect nonce validation on the wpecpp_settingsoptions function. This makes it possible for unauthenticated attackers to inject mal...

CVSS:
5.4
Affected:
up to 1.7.3
Fixed in:
1.7.3
Disclosed:
Jun 12, 2017

Easy PayPal &amp; Stripe Buy Now Button [wp-ecommerce-paypal] < 1.7.3

unknown

The Easy PayPal Buy Now Button plugin for WordPress is vulnerable to Cross-Site Request Forgery to Cross-Site Scripting in versions up to, and including, 1.7.2. This is due to missing or incorrect nonce validation on the wpecpp_settingsoptions function. This makes it possible for unauthenticated attackers to inject mal...

Affected:
up to 1.7.3
Fixed in:
1.7.3
Disclosed:
Jun 12, 2017

Easy PayPal &amp; Stripe Buy Now Button [wp-ecommerce-paypal] < 1.7.3

unknown

The plugin does not have CSRF check in place when saving its settings, and does not sanitise as well as escape them when output in the page. As a result, an attacker could make a logged in admin change them via. CSRF attack and perform Cross-Site Scripting attacks. The plugin also fixed a Reflected XSS in web browse...

Affected:
up to 1.7.3
Fixed in:
1.7.3

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database