Payment Button for PayPal <= 1.2.3.44 - Unauthenticated Payment Bypass
medium
The Payment Button for PayPal plugin for WordPress is vulnerable to Payment Bypass in all versions up to, and including, 1.2.3.44. This makes it possible for unauthenticated attackers to bypass payments.
- CVSS:
- 5.3
- Affected:
- up to 1.2.3.44
- Fix:
- No patched version reported
- Disclosed:
- Aug 5, 2026
CVE-2026-16990 on NVD →
Payment Button for PayPal [wp-paypal] < 1.2.3.42
unknown
[en] The Payment Button for PayPal plugin for WordPress is vulnerable to unauthorized order creation in all versions up to, and including, 1.2.3.41. This is due to the plugin exposing a public AJAX endpoint (`wppaypalcheckout_ajax_process_order`) that processes checkout results without any authentication or server-side...
- Affected:
- up to 1.2.3.42
- Fixed in:
- 1.2.3.42
- Disclosed:
- Jan 17, 2026
CVE-2025-14463 on NVD →
Payment Button for PayPal <= 1.2.3.41 - Missing Authorization to Unauthenticated Arbitrary Order Creation
medium
The Payment Button for PayPal plugin for WordPress is vulnerable to unauthorized order creation in all versions up to, and including, 1.2.3.41. This is due to the plugin exposing a public AJAX endpoint (`wppaypalcheckout_ajax_process_order`) that processes checkout results without any authentication or server-side veri...
- CVSS:
- 5.3
- Affected:
- up to 1.2.3.41
- Fixed in:
- 1.2.3.42
- Disclosed:
- Jan 16, 2026
CVE-2025-14463 on NVD →
Payment Button for PayPal [wp-paypal] < 1.2.3.36
unknown
[en] The Payment Button for PayPal plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wp_paypal_checkout' shortcode in all versions up to, and including, 1.2.3.35 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authentic...
- Affected:
- up to 1.2.3.36
- Fixed in:
- 1.2.3.36
- Disclosed:
- Jan 17, 2025
CVE-2024-13401 on NVD →
Payment Button for PayPal <= 1.2.3.35 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Payment Button for PayPal plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wp_paypal_checkout' shortcode in all versions up to, and including, 1.2.3.35 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated...
- CVSS:
- 6.4
- Affected:
- up to 1.2.3.35
- Fixed in:
- 1.2.3.36
- Disclosed:
- Jan 16, 2025
CVE-2024-13401 on NVD →
WP PayPal <= 1.2.3.8 - Cross-Site Scripting
medium
The WP PayPal plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 1.2.3.8 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser.
- CVSS:
- 6.1
- Affected:
- up to 1.2.3.7
- Fixed in:
- 1.2.3.8
- Disclosed:
- Jul 6, 2022
Payment Button for PayPal [wp-paypal] < 1.2.3.8
unknown
The WP PayPal plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 1.2.3.8 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser.
- Affected:
- up to 1.2.3.8
- Fixed in:
- 1.2.3.8
- Disclosed:
- Jul 6, 2022
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database