Impact
The Donation Block for PayPal plugin contains an improper neutralization of user input when rendering pages, leading to stored cross‑site scripting. Malicious data entered by an attacker can be saved and later injected into web pages served to visitors, enabling the execution of arbitrary client‑side code. This flaw resides in the plugin’s content handling routines and can affect the confidentiality and integrity of site traffic.
Affected Systems
WordPress sites using Bharat Kambariya’s Donation Block for PayPal plugin version 2.2.0 or earlier are vulnerable. No other vendors or product lines are listed in the CNA data.
Risk and Exploitability
The CVSS score of 6.5 classifies the risk as moderate, whereas the EPSS score of less than 1 % indicates a low chance of widespread exploitation at the current time. The flaw is not part of the CISA KEV catalog. Based on the description, an attacker could inject malicious content through the plugin’s data entry points, which may be accessed via the administrative interface or exposed donation forms. The resulting payload would execute in the context of any user who views the affected page, but would not provide direct system‑level privileges.
OpenCVE Enrichment
EUVD