WordPress security changelog
MEDIUM CVE-2025-68602 Deferred

Accept Donations with PayPal & Stripe: An open redirect

Accept Donations with PayPal & Stripe is affected by an open redirect. Exposure depends on how the affected operation is made reachable by the site. A crafted link can redirect visitors from the trusted site to an attacker-controlled destination.

CVE / CNA score 4.7 CVSS 3.1 · audit@patchstack.com
NVD score Pending NVD has not published its own CVSS assessment.
Component
Accept Donations with PayPal & Stripe
Plugin slug
easy-paypal-donation
Affected
See vendor advisory
Safe version
See mitigation notes
Published
Dec 24, 2025
Weakness
CWE-601 — URL Redirection to Untrusted Site ('Open Redirect')

This CVE was published Dec 24, 2025 and is one of 3 known issues for this plugin.

Patch or disable the affected component.

Update Accept Donations with PayPal & Stripe to a release outside the affected range, or disable and remove it until a fixed version is available.

Technical description

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Scott Paterson Accept Donations with PayPal & Stripe easy-paypal-donation allows Phishing.This issue affects Accept Donations with PayPal & Stripe: from n/a through <= 1.5.2.

CVE / CNA vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N

Primary and upstream sources