Executive brief
The Accept Donations with PayPal & Stripe plugin for WordPress, which allows websites to easily collect payments and donations, is vulnerable to a security flaw. An attacker with contributor-level access can inject malicious scripts into the website. If a site administrator or visitor views the affected content, these scripts could lead to unauthorized actions, website defacement, or the theft of sensitive session information.
Technical details
A Stored Cross-Site Scripting (XSS) vulnerability exists in the 'Accept Donations with PayPal & Stripe' plugin (easy-paypal-donation) for WordPress in versions up to and including 1.5.5. The flaw is caused by improper neutralization of input during web page generation (CWE-79). An attacker with 'Contributor' level privileges can inject malicious JavaScript payloads into plugin-related fields or content. The attack requires a victim (typically an administrator) to interact with the malicious content or visit a crafted page. Successful exploitation allows the execution of arbitrary scripts in the context of the victim's browser, potentially leading to session hijacking or unauthorized administrative actions. The issue is resolved in version 1.5.6.
Affected products
- Scott Paterson Accept Donations with PayPal & Stripe <= 1.5.5
Timeline
- 2026-07-13: disclosed: Reported by Ananda Dhakal via Patchstack
- 2026-07-23: advisory: NVD and Patchstack published the advisory
- 2026-07-23: patched: Fixed in version 1.5.6