Impact
The vulnerability allows stored cross‑site scripting (XSS) where a malicious script can be embedded into the plugin’s web pages. An attacker who can inject content would be able to run arbitrary JavaScript in the browsers of site visitors, potentially leading to cookie theft, phishing, or unauthorized actions performed on behalf of users. The flaw is inherent to improper input neutralisation and is a classic example of CWE‑79.
Affected Systems
WordPress sites using the wpecommerce Recurring PayPal Donations plugin version 1.8 or earlier are impacted. The affected product is the PayPal Donations plugin distributed by the wpecommerce vendor. No specific sub‑versions are listed, so any release up to and including 1.8 is considered vulnerable.
Risk and Exploitability
The CVSS score of 5.9 indicates a medium risk. The EPSS score of less than 1% shows a low probability of current exploitation, and the vulnerability is not listed in CISA’s KEV catalog. As a stored XSS flaw, exploitation allows an attacker to embed arbitrary JavaScript that will execute in visitors’ browsers when site content is viewed.
OpenCVE Enrichment
EUVD