VendorsTips and Tricks HQwordpress_simple_paypal_shopping_cartall versions
Vulnerabilities

Tips and Tricks HQ tipsandtricks-hq WordPress Simple Paypal Shopping Cart plugin

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

7CVEs
CVE-2013-2705
Cross-site request forgery (CSRF) vulnerability in the WordPress Simple Paypal Shopping Cart plugin before 3.6 for WordPress allows remote attackers to hijack the authentication of administrators for requests that change plugin settings.
Published 2014-05-13 · Modified
6.8EPSS 0.011
CVE-2025-3874
WordPress Simple PayPal Shopping Cart <= 5.1.3 - Insecure Direct Object Reference
Published 2025-05-01 · Analyzed
6.5EPSS 0.004
CVE-2025-3890
WordPress Simple PayPal Shopping Cart <= 5.1.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
Published 2025-05-01 · Analyzed
6.4EPSS 0.003
CVE-2022-4672
WordPress Simple Shopping Cart < 4.6.2 - Contributor+ Stored XSS via Shortcode
Published 2023-01-23 · Modified
5.4EPSS 0.005
CVE-2023-1431
The WP Simple Shopping Cart plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 4.6.3 due to the plugin saving shopping cart data exports in a publicly accessible location (/wp-content/plugins/wordpress-simple-paypal-shopping-cart/includes/admin/). This makes it possible for unauthenticated attackers to view information that should be limited to administrators only and can include data like first name, last name, email, address, IP Address, and more.
Published 2023-03-16 · Modified
5.3EPSS 0.005
CVE-2025-3889
WordPress Simple PayPal Shopping Cart <= 5.1.3 - Insecure Direct Object Reference via 'quantity'
Published 2025-05-01 · Analyzed
5.3EPSS 0.003
CVE-2023-6497
WordPress Simple Shopping Cart <= 4.7.1 - Authenticated(Administrator+) Stored Cross-Site Scripting
Published 2024-01-27 · Modified
4.8EPSS 0.003