What the vulnerability does
01Description
Improper Validation of Specified Quantity in Input vulnerability in Tips and Tricks HQ WP Express Checkout (Accept PayPal Payments) allows Manipulating Hidden Fields.This issue affects WP Express Checkout (Accept PayPal Payments): from n/a through 2.3.7.
Explanation of Vulnerability in Simple Terms
02Summary
WP Express Checkout versions up to 2.3.7 contain an integrity vulnerability allowing unauthenticated attackers to modify data over the network. The vulnerability requires no user interaction and can alter critical information processed by the plugin. Site administrators should update immediately to a version newer than 2.3.7.
What an attacker can do
03Attacker Capabilities
Modify data processed by the payment plugin without authentication.
Potential impact on your site
04Site Impact
Payment transactions or plugin settings could be altered by remote attackers, potentially affecting order integrity.
Conditions required to exploit
05Prerequisites
Network access only; no authentication or user interaction required.
Key dates
06Disclosure timeline
May 17, 2024
CVE published
April 28, 2026
Record updated