Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2024-5448

The PayPal Pay Now, Buy Now, Donation and Cart Buttons Shortcode WordPress plugin through 1.7 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks
Exploit prediction scoring system (EPSS) score
EPSS Score 0.003
EPSS Ranking 54.6%
CVSS Severity
CVSS v3 Score 5.4
Products affected by CVE-2024-5448
  • None » None » Version:
    _buy_now
  • None » None » Version:
    _donation_and_cart_buttons_shortcode:-
  • None » None » Version:
    _donation_and_cart_buttons_shortcode:1.7
  • Mohsinrasool » Paypal Pay Now » Version: Any
    cpe:2.3:a:mohsinrasool:paypal_pay_now


Contact Us

Shodan ® - All rights reserved