[Forgot Password]
Login  Register Subscribe

23631

 
 

126951

 
 

99602

 
 

909

 
 

80167

 
 

109

Paid content will be excluded from the download.


Download | Alert*
CVE
view XML

CVE-2015-7666

Date: (C)2017-12-29   (M)2018-01-05 


Multiple cross-site scripting (XSS) vulnerabilities in the (1) cp_updateMessageItem and (2) cp_deleteMessageItem functions in cp_ppp_admin_int_message_list.inc.php in the Payment Form for PayPal Pro plugin before 1.0.2 for WordPress allow remote attackers to inject arbitrary web script or HTML via the cal parameter.

CVSS Score: 10.0Access Vector:
Exploit Score: Access Complexity:
Impact Score: Authentication:
 Confidentiality:
 Integrity:
 Availability:





Reference:
http://www.securityfocus.com/archive/1/archive/1/536602/100/0/threaded
https://plugins.trac.wordpress.org/changeset/1254452/payment-form-for-paypal-pro
https://wordpress.org/plugins/payment-form-for-paypal-pro/#developers
https://wpvulndb.com/vulnerabilities/8210

© 2013 SecPod Technologies