Impact
The vulnerability, identified as CWE-79 (Cross‑Site Scripting), permits a remote attacker to inject arbitrary JavaScript into a WordPress site using the Easy PayPal Buy Now Button plugin. Because authentication is not required, any visitor to the affected site can be tricked into executing malicious code, which may steal session cookies, hijack user sessions, or deface the site.
Affected Systems
WordPress sites that have the Easy PayPal Buy Now Button plugin from Scott Paterson, version 2.0.4 or earlier. Updating the plugin to the latest release, 2.0.5 or newer, removes the flaw.
Risk and Exploitability
The CVSS score of 7.1 indicates a high impact capability for attackers. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, but the lack of authentication and the user‑agent execution path make it relatively easy to exploit via crafted URLs or integrated form data.
OpenCVE Enrichment