Stored Cross-Site Scripting Vulnerability in WordPress PayPal Donation Plugin
CVE-2026-4072

6.4MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
21 March 2026

What is CVE-2026-4072?

The WordPress PayPal Donation plugin is vulnerable to Stored Cross-Site Scripting (XSS), allowing authenticated users with Contributor-level access and above to inject malicious scripts via the 'donate' shortcode. This vulnerability arises from inadequate input sanitization and improper output escaping of user-supplied shortcode attributes, including 'amount', 'email', 'title', 'return_url', 'cancel_url', 'ccode', and 'image'. When these values are processed and displayed without escaping directly within HTML attribute values, it enables the injection of arbitrary web scripts, which can execute whenever a user accesses an affected page.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

WordPress PayPal Donation * <= 1.01

References

CVSS V3.1

Score:
6.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Gilang Asra Bilhadi
.