Sceawere

Vulnerability Detail

CVE-2026-65517UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Easy PayPal Buy Now Button XSS

Vulnerability Metadata

Severity
High
Score / CVSS
7.1
Creation Date
1d ago
Vendor
Scott Paterson
Product
Easy PayPal Buy Now Button
Attack Type
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
Attack Complexity
LOW

Narrative and Response

Description

Unauthenticated Cross Site Scripting (XSS) in Easy PayPal Buy Now Button <= 2.0.4 versions.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.1",
  "pubDate": "2026-08-06T15:17:15.483Z",
  "pubdate": "2026-08-06T15:17:15.483Z",
  "executiveSummary": "An unauthenticated Cross-Site Scripting (XSS) vulnerability has been identified in the Easy PayPal Buy Now Button plugin. This security flaw allows remote, unauthenticated threat actors to inject malicious client-side scripts, typically JavaScript, into vulnerable web pages rendered by the affected software.\nThe primary impact of this vulnerability involves the execution of arbitrary script code in the context of a victim's browser session. If successfully exploited, an attacker could hijack user sessions, steal sensitive authentication cookies, redirect users to malicious external domains, or deface the hosting website.\nThe vulnerability affects Easy PayPal Buy Now Button versions 2.0.4 and prior. Systems running these vulnerable versions are directly exposed to risk if they render user-supplied input without proper sanitization or context-aware output encoding.\nExploitation requires no prior authentication or elevated privileges, lowering the barrier to entry for attackers. The attack vector is network-based, typically requiring a victim to interact with a maliciously crafted URL or input vector processed by the plugin.\nOrganizations utilizing the affected plugin face significant integrity and confidentiality risks regarding their web application front-end. Immediate remediation is required to prevent unauthorized script execution and safeguard client-side application security.",
  "technicalDetails": "The vulnerability resides in the Easy PayPal Buy Now Button plugin, specifically affecting versions 2.0.4 and below. The root cause stems from insufficient input validation and a lack of proper output encoding on parameters processed and rendered by the vulnerable component.\nBecause the vulnerability is unauthenticated, an external attacker can interact directly with the web application over the network without needing valid user credentials or administrative privileges. The attack surface is exposed via HTTP/HTTPS protocols where user-supplied parameters are improperly handled.\nThe exploitation method relies on injecting malicious payloads, such as HTML or JavaScript tags, into vulnerable input fields or URL parameters processed by the plugin. When the web application generates the response, it fails to sanitize or neutralize the injected payload before reflecting it back to the client browser.\nThe step-by-step attack flow begins with the threat actor crafting a malicious URL containing the XSS payload targeting a vulnerable endpoint handled by the Easy PayPal Buy Now Button plugin. The attacker then induces a target user to click the crafted link or visit the compromised page via social engineering or other delivery mechanisms.\nUpon rendering the page, the victim's browser parses the HTTP response and executes the injected script within the security context of the victim's session. The payload behavior can range from benign proof-of-concept alerts to malicious actions such as accessing the Document Object Model (DOM), exfiltrating session tokens, or performing unauthorized actions on behalf of the authenticated user.\nThe post-exploitation impact includes session hijacking, credential theft, and unauthorized manipulation of the web interface. Due to the client-side nature of the flaw, the malicious script operates with the full privileges of the victim's browser session against the vulnerable web application."
}
CVE-2026-65517: Easy PayPal Buy Now Button XSS (HIGH Severity, CVSS: 7.1) - Sceawere