The plugin does not sanitize and escapes some parameters, which could allow users with a role as low as Contributor to perform Cross-Site Scripting attacks.
Put the following shortcode in a blog post: [paypal_donation_button align='center" onmouseover="alert(1)']
Lana Codes
Lana Codes
Yes
2022-11-16 (about 6 months ago)
2022-11-16 (about 6 months ago)
2022-12-05 (about 5 months ago)