id: CVE-2025-68602 info: name: Accept Donations with PayPal <= 1.5.2 - Open Redirect author: Shivam Kamboj severity: medium description: | The Accept Donations with PayPal & Stripe plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 1.5.2. This is due to insufficient validation on the redirect url supplied. This makes it possible for unauthenticated attackers to redirect users to potentially malicious sites if they can successfully trick them into performing an action. impact: | Attackers can redirect users to malicious sites, facilitating phishing attacks and credential theft. remediation: | Update to the latest version beyond 1.5.1. reference: - https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/easy-paypal-donation/accept-donations-with-paypal-152-unauthenticated-open-redirect - https://nvd.nist.gov/vuln/detail/CVE-2025-68602 classification: cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N cvss-score: 4.7 cve-id: CVE-2025-68602 epss-score: 0.00448 epss-percentile: 0.36619 cwe-id: CWE-601 metadata: verified: true max-request: 1 tags: cve,cve2025,wordpress,wp,wp-plugin,redirect,easy-paypal-donation,unauth http: - method: GET path: - "{{BaseURL}}/?wpedon-stripe-checkout-redirect=1&sk=nucleitest&ai=nucleitest&si=nucleitest&rf=//oast.pro" matchers-condition: and matchers: - type: status status: - 200 - type: word part: body words: - 'src="https://js.stripe.com/v3/"' - type: word part: body words: - "let rf = '//oast.pro" - type: word part: body words: - "window.location.href = rf;" extractors: - type: regex name: open-redirect part: body regex: - "let rf = '([^']+)'" # digest: 4a0a00473045022100e6a1a538c8da7bb4b9b1c58b410d90bfd6a3e305b76ccc6f1dd87f333b3ae1eb02205303c8a584075d81faa6bd220e3467b7a698a91ea97023ce596ee7d9843e4d9e:922c64590222798bb761d5b6d8e72950