Input validation vulnerability in Checkout for PayPal 1.0.32

The Checkout for PayPal plugin used in WordPress has a security issue called Stored Cross-Site Scripting. This happens when the plugin’s ‘checkout_for_paypal’ shortcode is used. This vulnerability exists in all versions up to 1.0.32 because it does not properly check and remove harmful code that users may input. This allows attackers with contributor-level access or higher to insert their own malicious code into pages, which will then be executed whenever a user visits that page.

Detected in:

Checkout for PayPal fixed vulnerable versions: >= * <= 1.0.32

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.