plugin

Wp Paypal Vulnerabilities

7 known security issues reported for the Wp Paypal WordPress plugin. Most recent disclosed Aug 5, 2026.

4 medium

Running Wp Paypal on your site? Check whether your installed version is affected.

Scan your site free

Payment Button for PayPal <= 1.2.3.44 - Unauthenticated Payment Bypass

medium

The Payment Button for PayPal plugin for WordPress is vulnerable to Payment Bypass in all versions up to, and including, 1.2.3.44. This makes it possible for unauthenticated attackers to bypass payments.

CVSS:
5.3
Affected:
up to 1.2.3.44
Fix:
No patched version reported
Disclosed:
Aug 5, 2026

CVE-2026-16990 on NVD →

Payment Button for PayPal [wp-paypal] < 1.2.3.42

unknown

[en] The Payment Button for PayPal plugin for WordPress is vulnerable to unauthorized order creation in all versions up to, and including, 1.2.3.41. This is due to the plugin exposing a public AJAX endpoint (`wppaypalcheckout_ajax_process_order`) that processes checkout results without any authentication or server-side...

Affected:
up to 1.2.3.42
Fixed in:
1.2.3.42
Disclosed:
Jan 17, 2026

CVE-2025-14463 on NVD →

Payment Button for PayPal <= 1.2.3.41 - Missing Authorization to Unauthenticated Arbitrary Order Creation

medium

The Payment Button for PayPal plugin for WordPress is vulnerable to unauthorized order creation in all versions up to, and including, 1.2.3.41. This is due to the plugin exposing a public AJAX endpoint (`wppaypalcheckout_ajax_process_order`) that processes checkout results without any authentication or server-side veri...

CVSS:
5.3
Affected:
up to 1.2.3.41
Fixed in:
1.2.3.42
Disclosed:
Jan 16, 2026

CVE-2025-14463 on NVD →

Payment Button for PayPal [wp-paypal] < 1.2.3.36

unknown

[en] The Payment Button for PayPal plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wp_paypal_checkout' shortcode in all versions up to, and including, 1.2.3.35 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authentic...

Affected:
up to 1.2.3.36
Fixed in:
1.2.3.36
Disclosed:
Jan 17, 2025

CVE-2024-13401 on NVD →

Payment Button for PayPal <= 1.2.3.35 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Payment Button for PayPal plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wp_paypal_checkout' shortcode in all versions up to, and including, 1.2.3.35 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated...

CVSS:
6.4
Affected:
up to 1.2.3.35
Fixed in:
1.2.3.36
Disclosed:
Jan 16, 2025

CVE-2024-13401 on NVD →

WP PayPal <= 1.2.3.8 - Cross-Site Scripting

medium

The WP PayPal plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 1.2.3.8 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser.

CVSS:
6.1
Affected:
up to 1.2.3.7
Fixed in:
1.2.3.8
Disclosed:
Jul 6, 2022

Payment Button for PayPal [wp-paypal] < 1.2.3.8

unknown

The WP PayPal plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 1.2.3.8 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser.

Affected:
up to 1.2.3.8
Fixed in:
1.2.3.8
Disclosed:
Jul 6, 2022

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database