Stored Cross-Site Scripting Vulnerability in Checkout for PayPal Plugin
CVE-2024-13398
6.4MEDIUM
What is CVE-2024-13398?
The Checkout for PayPal plugin for WordPress is susceptible to a Stored Cross-Site Scripting vulnerability due to inadequate input sanitization and output escaping on user-supplied attributes via the 'checkout_for_paypal' shortcode. This flaw allows authenticated attackers, with at least contributor-level access, to inject arbitrary web scripts into pages. These malicious scripts can execute whenever a user accesses the compromised page, potentially leading to serious security breaches and exploitation of user data.
Affected Version(s)
Checkout for PayPal * <= 1.0.32