CVE-2025-22525
CVSS 3.1 Score 6.5 of 10 (medium)
Details
Summary
CVE-2025-22525 is a Cross-site Scripting (XSS) vulnerability affecting the Donation Block For PayPal from version n/a to 2.2.0. This issue arises due to improper neutralization of user input during web page generation. The consequence is the storage of malicious scripts, which can be executed in the victim's browser upon visiting a crafted webpage. Attackers can exploit this vulnerability to steal sensitive information, install malware, or perform other malicious activities. Users are advised to update their Donation Block For PayPal to the latest version to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.