Vulnerabilities > Fullworksplugins > Quick Paypal Payments > 5.6.1

DATE CVE VULNERABILITY TITLE RISK
2023-05-02 CVE-2023-1554 Unspecified vulnerability in Fullworksplugins Quick Paypal Payments
The Quick Paypal Payments WordPress plugin before 5.7.26.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
network
low complexity
fullworksplugins
4.8
2023-04-25 CVE-2023-23889 Cross-site Scripting vulnerability in Fullworksplugins Quick Paypal Payments
Auth.
network
low complexity
fullworksplugins CWE-79
5.4
2023-04-07 CVE-2023-25702 Cross-site Scripting vulnerability in Fullworksplugins Quick Paypal Payments
Auth.
network
low complexity
fullworksplugins CWE-79
4.8
2023-04-07 CVE-2023-25713 Cross-site Scripting vulnerability in Fullworksplugins Quick Paypal Payments
Unauth.
network
low complexity
fullworksplugins CWE-79
6.1