Payment Button for PayPal

Payment Button for PayPal has 4 disclosed vulnerabilities in the WordSec catalog, reported between 2022 and 2026; all 4 are fixed as of September 2026. Their average CVSS score is 5.8, and the most serious one scores 6.4 out of 10. 2026 was the busiest year with 2 disclosures.

The most common weakness is Cross-Site Scripting, behind 2 of the records (50%). Other recurring categories include Missing Authorization.

Every one of the 4 issues recorded for Payment Button for PayPal has a vendor fix available, so running the current release closes all known holes.

3 independent researchers contributed these findings, one record each. Payment Button for PayPal is installed on roughly 4,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.1.

Strategic Overview

Avg CVSSMedium
5.8/ 10
Patch Coverage100%
Open

0

Fixed

4

Get automatic notifications for all Payment Button for PayPal vulnerabilities before they are exploited.

Highest severity on recordCVSS 6.4CVE-2024-13401

Payment Button for PayPal <= 1.2.3.35 - Authenticated (Contributor+) Stored Cross-Site Scripting

Read the full analysis

Vulnerability Records

4 records
Plugin Profile
Latestv1.2.3.46

Payment Button for PayPal

Noor Alam

Author

Noor Alam

4.5(40)
90/100
Last Updated
2026-09-02 (11d ago)
Active Installs
4,000+
Downloads
572,291
Requires WP
5.3+
Requires PHP
0+
Tested up to
WP 7.1
Created
2015-02-16 (12y ago)

Payment Button for PayPal plugin (also known as WP PayPal) allows you to easily create PayPal Buy Now buttons. It generates dynamic buttons using shortcodes that enable PayPal checkout on your WordPress site. Your customers will be able to pay for your products using PayPal or Credit Card. This plugin makes it easy for you to set up your online e-commerce store. Payment Button for PayPal supports PayPal Sandbox. PayPal Sandbox is a simulation environment which allows you to do test purchases between a test buyer and a seller account. This is to make sure that your store can process PayPal transactions without any issues. It also helps you get prepared before selling to real customers. Payment Button for PayPal Features Sell products or services using PayPal Create PayPal buttons in a post/page using shortcodes Accept once off payments Accept donations from users View or Manage orders received via PayPal buttons from your WordPress admin dashboard Quick settings configurations Enable debug to troubleshoot various issues (e.g. orders not getting updated) Open PayPal log to see how order are being processed Accept debit or credit card payments Switch your store to PayPal sandbox mode for testing Sell in any currency supported by PayPal Charge shipping on your products or services Send a purchase confirmation email to your customer after a transaction Send a sale notification email to one or more recipients (e.g. the seller) after a transaction Accept payments with PayPal smart payment buttons Accept Pay Later Pay in 4 payments Note: This is NOT an official PayPal product. How to Use Payment Button for PayPal Once you have installed this plugin you need to go to the settings menu to configure some PayPal settings (WP PayPal -> Settings). PayPal Checkout Settings Client ID: The client ID for your PayPal REST API app Secret Key: The secret key for your PayPal REST API app Currency Code: The default currency code for payments Return URL: The redirect URL after a successful payment Cancel URL: The redirect URL when a payment is cancelled Checkout Page URL: The URL of the page where PayPal checkout options will appear How to Create a Buy Now Button To create a Buy Now button create a product first (WP PayPal -> Products). Now insert the shortcode into a page like the following: [wp_paypal_product id="1"] Replace 1 with the actual product ID. How to Create a PayPal Checkout Page To create a PayPal checkout page insert the shortcode into a page like the following. [wp_paypal_checkout] This is where payment options will appear. For more information check the PayPal Checkout documentation page. Payment Button for PayPal Emails Payment Button for PayPal plugin comes with an “Emails” tab where you will be able to configure some email related settings. Email Sender Options In this section you can choose to customize the default From Name and From Email Address that will be used when sending an email. Purchase Receipt Email When this feature is enabled an email sent to the customer after completion of a successful purchase. Options you can customize here: The subject of the purchase receipt email The content type of the purchase receipt email. The default is “Plain Text”. But you can also set it to “HTML” The body of the purchase receipt email. Sale Notification Email When this feature is enabled an email is sent to your chosen recipient(s) after completion of a successful purchase. Options you can customize here: The subject of the sale notification email The content type of the sale notification email. The default is “Plain Text”. But you can also set it to “HTML” The body of the sale notification email. You can use various email tags in the subject/body of an email to dynamically change its content. You can find the full list of available email tags in the WordPress PayPal plugin page. Can the email messages be sent over SMTP? Absolutely. The following SMTP plugins have been tested: SMTP Mailer Gmail SMTP WP Mail SMTP Post SMTP FluentSMTP Easy WP SMTP

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C