The Accept Donations with PayPal WordPress plugin before 1.3.1 offers a function to create donation buttons, which internally are posts. The process to create a new button is lacking a CSRF check. An attacker could use this to make an authenticated admin create a new button. Furthermore, one of the Button field is not escaped before being output in an attribute when editing a Button, leading to a Stored Cross-Site Scripting issue as well.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: WPScan
Published: 2021-11-01T08:46:00
Updated: 2024-08-03T19:35:20.193Z
Reserved: 2021-01-14T00:00:00
Link: CVE-2021-24570
Vulnrichment
No data.
NVD
Status : Modified
Published: 2021-11-01T09:15:08.503
Modified: 2024-11-21T05:53:19.647
Link: CVE-2021-24570
Redhat
No data.