4.3
CVSSv2

CVE-2015-7666

Published: 27/12/2017 Updated: 26/07/2019
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.1 | Impact Score: 2.7 | Exploitability Score: 2.8
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Multiple cross-site scripting (XSS) vulnerabilities in the (1) cp_updateMessageItem and (2) cp_deleteMessageItem functions in cp_ppp_admin_int_message_list.inc.php in the Payment Form for PayPal Pro plugin prior to 1.0.2 for WordPress allow remote malicious users to inject arbitrary web script or HTML via the cal parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

codepeople payment form for paypal pro

Exploits

WordPress DWBooster Payment Form for PayPal Pro plugin version 101 suffers from a cross site scripting vulnerability ...