CVE-2024-5448

June 21, 2024, 11:22 a.m.

Product(s) Impacted

PayPal Pay Now, Buy Now, Donation and Cart Buttons Shortcode WordPress plugin

  • through 1.7

Description

The PayPal Pay Now, Buy Now, Donation and Cart Buttons Shortcode WordPress plugin through 1.7 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

Weaknesses

Date

Published: June 21, 2024, 6:15 a.m.

Last Modified: June 21, 2024, 11:22 a.m.

Status : Undergoing Analysis

CVE has been recently published to the CVE List and has been received by the NVD.

More info

Source

contact@wpscan.com

References