Extension WordPress
Vulnérabilités Accept Donations with PayPal & Stripe
Cette page rassemble les failles publiées pour Accept Donations with PayPal & Stripe, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Accept Donations with PayPal & Stripe
8 fiches
Accept Donations with PayPal <= 1.5.2 – Unauthenticated Open Redirect
The Accept Donations with PayPal & Stripe plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 1.5.2. This is due to insufficient validation on the redirect url supplied. This makes it possible…
*-1.5.2
1.5.3
25/12/2025
Accept Donations with PayPal <= 1.4.5 – Cross-Site Request Forgery to Stored Cross-Site Scripting
The Accept Donations with PayPal & Stripe plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.4.5. This is due to missing or incorrect nonce validation on the render() function. This…
*-1.4.5
1.5
07/05/2025
Accept Donations with PayPal & Stripe <= 1.4.4 – Reflected Cross-Site Scripting
The Accept Donations with PayPal & Stripe plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the rf parameter in all versions up to, and including, 1.4.4 due to insufficient input sanitization and output escaping. This makes…
*-1.4.4
1.4.5
22/02/2025
Accept Donations with PayPal <= 1.3 – Reflected Cross-Site Scripting via Page
The Accept Donations with PayPal plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘page’ parameter in versions up to, and including, 1.3 due to insufficient input sanitization and output escaping. This makes it possible for…
*-1.3
1.3.1
25/05/2022
Accept Donations with PayPal <= 1.3.3 – Arbitrary Post Deletion via Cross-Site Request Forgery
The Accept Donations with PayPal WordPress plugin before 1.3.4 does not have CSRF check in place and does not ensure that the post to be deleted belongs to the plugin, allowing attackers to make a logged in admin…
*-1.3.3
1.3.4
09/12/2021
Paypal Donation <= 1.3.1 – Admin+ Stored Cross-Site Scripting
The Accept Donations with PayPal WordPress plugin before 1.3.2 does not escape the Amount Menu Name field of created Buttons, which could allow a high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is…
*-1.3.1
1.3.2
18/10/2021
Accept Donations with PayPal <= 1.3.0 Cross-Site Request Forgery to Post Deletion
The Accept Donations with PayPal WordPress plugin before 1.3.1 provides a function to create donation buttons which are internally stored as posts. The deletion of a button is not CSRF protected and there is no control to check…
[*, 1.3.1)
1.3.1
04/10/2021
Paypal Donation <= 1.3 – Cross-Site Request Forgery to Stored Cross-Site Scripting
The Accept Donations with PayPal WordPress plugin before 1.3.1 offers a function to create donation buttons, which internally are posts. The process to create a new button is lacking a CSRF check. An attacker could use this to…
*-1.3
1.3.1
04/10/2021
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.