What the vulnerability does
01Description
Contributor Cross Site Scripting (XSS) in Accept Donations with PayPal & Stripe <= 1.5.5 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L
What the vulnerability does
Contributor Cross Site Scripting (XSS) in Accept Donations with PayPal & Stripe <= 1.5.5 versions.
Explanation of Vulnerability in Simple Terms
A cross-site scripting (XSS) vulnerability in Accept Donations with PayPal & Stripe allows authenticated users to inject malicious scripts that execute in other users' browsers. The vulnerability requires user interaction—typically clicking a malicious link—and can affect site visitors across the platform. Attackers with low-level access can craft payloads that steal session data or perform actions on behalf of victims.
What an attacker can do
Inject malicious scripts that execute in other users' browsers and steal session data or perform unauthorized actions.
Potential impact on your site
Visitors and staff may have their sessions hijacked or be tricked into performing unintended actions on your site.
Conditions required to exploit
Attacker must have a low-level user account and trick a victim into clicking a malicious link or visiting a crafted page.
Key dates
External resources
Related vulnerabilities