Stored Cross-Site Scripting Vulnerability in WordPress PayPal Donation Plugin
CVE-2026-4072
What is CVE-2026-4072?
The WordPress PayPal Donation plugin is vulnerable to Stored Cross-Site Scripting (XSS), allowing authenticated users with Contributor-level access and above to inject malicious scripts via the 'donate' shortcode. This vulnerability arises from inadequate input sanitization and improper output escaping of user-supplied shortcode attributes, including 'amount', 'email', 'title', 'return_url', 'cancel_url', 'ccode', and 'image'. When these values are processed and displayed without escaping directly within HTML attribute values, it enables the injection of arbitrary web scripts, which can execute whenever a user accesses an affected page.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
WordPress PayPal Donation * <= 1.01