CVE-2025-46499

CVSS 3.1 Score 7.1 of 10 (high)

Details

Published Apr 24, 2025
Updated: Apr 29, 2025
CWE ID 79

Summary

CVE-2025-46499 is a Cross-site Scripting (XSS) vulnerability affecting PayPal Express Checkout versions from n/a to 2.1.2. Hackers can exploit this Improper Neutralization of Input issue during web page generation to inject malicious scripts into a targeted user's browser. These scripts can then be used to steal sensitive information, such as login credentials or session tokens, or perform actions on behalf of the user. The vulnerability poses a significant risk as it allows for Stored XSS attacks, enabling the malicious code to remain active even after the initial exploit has been resolved. Users and administrators are strongly advised to update their PayPal Express Checkout installations as soon as possible to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share