Donations via PayPal
Donations via PayPal has one disclosed vulnerability in the WordSec catalog, all reported in 2022; it is fixed as of September 2026. Their average CVSS score is 5.5, and the most serious one scores 5.5 out of 10.
The most common weakness is Cross-Site Scripting, behind 1 of the records (100%).
The one issue recorded for Donations via PayPal has a vendor fix available, so running the current release closes it.
All of these findings were reported by zhangyunpei. Donations via PayPal is installed on roughly 20,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.1.
CVE-2022-3822Donations via PayPal <= 1.9.8 - Authenticated (Administrator+) Stored Cross-Site Scripting
Read the full analysisVulnerability Records

Donations via PayPal
Author
mra13 / Team Tips and Tricks HQ
Adds a PayPal donation shortcode and sidebar Widget to WordPress. The options menu lets you setup you PayPal ID and a few other optional settings. You can choose which donation button you want to use or if you want to use your own button. You can also set an optional default purpose and reference which can be overridden on each inserted instance with the shortcode options or in the Widget settings. There is also options available for currency, localization of the button, custom payment page style and the return page. Widget In the Appearance -> Widgets you’ll find the PayPal Donations widget. After adding it to your sidebar you can enter a title for the Widget, some descriptive text that will appear above the button and specify an optional purpose and reference for the donation button to override the default settings. Shortcode Insert the button in your pages or posts with this shortcode [paypal-donation] Which is the simplest option, and uses all default and optional settings. If you want to make a specific button for a specific purpose you can add additional options. Example: [paypal-donation purpose="Spline Importer" reference="3D Plugins"] This donation plugin generates valid XHTML Transitional and Strict code. Translations The following language translations are already available in the plugin: Albanian (sq_AL) Danish (da_DK) Dutch (nl_NL) French (fr_FR) German (de_DE) Hebrew (he_IL) Italian (it_IT) Lithuanian (lt_LT) Malay – Bahasa Melayu (ms_MY) Norwegian bokmål Romanian (ro_RO) Russian (ru_RU) Spanish (es_ES) Swedish (sv_SE) Turkish (tr_TR) Related Links Documentation Support Forum
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C