Impact
The Razorpay Payment Button plugin for WordPress contains an unauthenticated XSS flaw in all releases up to and including version 2.4.9. This weakness, identified as CWE‑79, permits the injection of script code into pages rendered by the plugin. An attacker who supplies malicious input can execute scripts in the context of a visitor’s browser, potentially leading to session hijacking, cookie theft, defacement or other downstream attacks. The CVSS score of 7.1 signals a moderate to high severity impact for affected installations.
Affected Systems
The flaw affects the Razorpay Payment Button plugin from Razorpay, used on WordPress sites. Versions up to and including 2.4.9 are vulnerable; upgrading to version 2.5.0 or newer mitigates the issue.
Risk and Exploitability
The XSS vulnerability is exploitable by any person who can craft a request to the plugin, with no authentication or special privileges required. Because it is unauthenticated and active on public‑facing sites, an attacker can target visitors simply by directing them to a vulnerable page. The EPSS score is not available, and the flaw is not listed in the CISA KEV catalog. However, the CVSS score of 7.1 and the straightforward exploitation path mean that the risk remains medium–high for sites that have not applied the available patch.
OpenCVE Enrichment