
Cloud Vulnerability DB
A community-led vulnerabilities database
The Easy PayPal & Stripe Buy Now Button plugin for WordPress contains a Cross-Site Request Forgery (CSRF) vulnerability in all versions up to and including 1.8.3, and in Contact Form 7 – PayPal & Stripe Add-on all versions up to and including 2.1. The vulnerability was discovered in February 2024 and is tracked as CVE-2024-1719 (NVD).
The vulnerability stems from missing or incorrect nonce validation in the 'wpecpp_stripe_connect_completion' function. The issue has been assigned a CVSS v3.1 base score of 4.3 (MEDIUM) with the vector string CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N (Wordfence).
The vulnerability allows unauthenticated attackers to modify the plugin's settings and change the stripe connection if they can trick a site administrator into performing specific actions, such as clicking on a malicious link (NVD).
The vulnerability requires user interaction to be exploited, specifically requiring an administrator to click on a malicious link. No known exploits in the wild have been reported at this time (NVD).
Updates have been released to address this vulnerability. Users should upgrade to versions newer than 1.8.3 of the Easy PayPal & Stripe Buy Now Button plugin or versions newer than 2.1 of the Contact Form 7 – PayPal & Stripe Add-on (NVD).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."