PT-2025-11699 · Unknown · Syliud Paypal Plugin

Published

2025-03-19

·

Updated

2025-03-19

·

CVE-2025-30152

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Syliud PayPal Plugin versions prior to 1.6.2 Syliud PayPal Plugin versions prior to 1.7.2 Syliud PayPal Plugin versions prior to 2.0.2
Description A discovered issue allows users to modify their shopping cart after completing the PayPal Checkout process and payment authorization. If a user initiates a PayPal transaction from a product page or the cart page and then returns to the order summary page, they can still manipulate the cart contents before finalizing the order. This can lead to a scenario where merchants deliver products or services without full payment.
Recommendations For versions prior to 1.6.2, update to version 1.6.2 or above. For versions prior to 1.7.2, update to version 1.7.2 or above. For versions prior to 2.0.2, update to version 2.0.2 or above.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-30152
GHSA-HXG4-65P5-9W37

Affected Products

Syliud Paypal Plugin