Quick Paypal Payments

Quick Paypal Payments has 9 disclosed vulnerabilities in the WordSec catalog, reported between 2013 and 2026; all 9 are fixed as of September 2026. Their average CVSS score is 5.9, and the most serious one scores 7.3 out of 10. Severity breakdown: 0 critical and 2 high. 2023 was the busiest year with 5 disclosures.

The most common weakness is Cross-Site Scripting, behind 5 of the records (56%). Other recurring categories include Missing Authorization, Cross-Site Request Forgery (CSRF).

Every one of the 9 issues recorded for Quick Paypal Payments has a vendor fix available, so running the current release closes all known holes.

5 independent researchers contributed these findings, most of them (4) reported by yuyudhn. Quick Paypal Payments is installed on roughly 1,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.1.

Strategic Overview

Avg CVSSMedium
5.9/ 10
Patch Coverage100%
Open

0

Fixed

9

Get automatic notifications for all Quick Paypal Payments vulnerabilities before they are exploited.

Highest severity on recordCVSS 7.3CVE-2023-25714

Quick Paypal Payments <= 5.7.25 - Missing Authorization

Read the full analysis

Vulnerability Records

9 records
Quick Paypal Payments banner
Latestv6.0.2

Quick Paypal Payments

fullworks

Author

fullworks

4.4(32)
88/100
Last Updated
2026-08-23 (20d ago)
Active Installs
1,000+
Downloads
235,947
Requires WP
6.0+
Requires PHP
7.4+
Tested up to
WP 7.1
Created
2012-10-13 (14y ago)

Take a PayPal payment today. One shortcode puts a payment form anywhere on your WordPress site. All it needs is your PayPal email address, so you can be taking money in a few minutes, with no business account, no API keys and no developer. Unlimited forms, any currency PayPal accepts, and every label and colour is yours to change. What the free version does Unlimited payment forms, placed with a shortcode, a block or a widget Any currency PayPal accepts Charge one set price, or let the buyer type the amount Quantity, item number, and a list of options to pick from Name, email, postal address and phone number, if you want to collect them Your own message field, terms and conditions, a consent tick box and a maths captcha Change every label, caption and colour, or leave the defaults alone A record of every payment, with a CSV download Mark a payment as paid by hand once you have checked it in PayPal Multi-language and GDPR ready A personal PayPal account is enough. There is nothing to configure beyond your email address. What the paid version adds The paid version is about getting your time back and selling more than one thing. Payments confirm themselves. PayPal tells your site the moment a payment clears, so orders mark themselves paid and you stop opening PayPal to check whether one went through. Your buyer gets an automatic thank you email, and you can create their WordPress account at the same time, in whichever role you choose. Take card payments as well as PayPal. Send buyers to Stripe instead and take cards directly, on a page hosted by Stripe so no card details touch your site. Some people will not pay through PayPal, and that is the reason they abandon a payment. Sell properly rather than just collect money. Offer a choice of prices on one form, a slider, or a set of pre-set references. Run coupon codes with percentage or fixed discounts, expiry dates and limited quantities. Add postage and handling as a fixed amount or a percentage. Set a minimum amount, or switch the form to donations. Charge again next month. Recurring payments through PayPal on a schedule you choose, stopping automatically after the number of payments you set. Recurring forms use PayPal even on a site that otherwise takes cards. Sell up to nine things at once, each with its own price and quantity, on one form. And the rest: a datepicker field, Mailchimp signup, your own logo on the PayPal checkout page, sandbox mode for testing, and support by email and knowledge base. See what is in each plan. PHP Tested up to PHP 8.5 Developers plugin page quick paypal payments plugin. External Services This plugin relies on PayPal to take payments. It cannot function without it. PayPal checkout When a visitor submits one of your payment forms, the plugin sends them to PayPal to complete the payment. The data submitted to PayPal is the payment amount, currency, item name and payment reference, together with any name, email address, postal address and telephone number the visitor entered on your form. This happens only at the point a visitor submits a payment form. On pages that contain a payment form, the plugin also loads PayPal’s checkout script from https://www.paypalobjects.com/api/checkout.js. PayPal Instant Payment Notification If you enable IPN, PayPal sends your site a notification when a payment is made. Your site posts that notification back to PayPal at https://ipnpb.paypal.com (or https://ipnpb.sandbox.paypal.com in sandbox mode) so PayPal can confirm it is genuine. Only the notification PayPal sent is posted back. PayPal terms of service: https://www.paypal.com/uk/legalhub/useragreement-full PayPal privacy policy: https://www.paypal.com/uk/legalhub/privacy-full Stripe (paid version only) The free version does not contain the Stripe integration and never contacts Stripe. In the paid version, if you enter your Stripe keys and switch Stripe on, submitting a payment form creates a checkout session at https://api.stripe.com and sends the visitor to a payment page hosted by Stripe. The data sent is the payment amount, currency, item name and, if your form collects it, the visitor’s email address. No card details are entered on or handled by your site. Stripe then notifies your site when the payment completes. Stripe terms of service: https://stripe.com/legal/ssa Stripe privacy policy: https://stripe.com/privacy Freemius Licensing, updates and optional usage tracking are handled by Freemius. Usage tracking is opt in and you are asked when the plugin is activated. If you opt in, your site URL, WordPress and PHP versions and the administrator email address are sent to Freemius. If you decline, no data is sent. Freemius terms of service: https://freemius.com/terms/ Freemius privacy policy: https://freemius.com/privacy/

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C