
CVE-2026-3617 The Paypal Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'amount' and 'name' shortcode attributes in all versions up to, and inclu… https://www.cve.org/CVERecord?id=CVE-2026-3617
Post summary
The text announces a stored XSS vulnerability in the PayPal Shortcode WordPress plugin (CVE‑2026‑3617) without mentioning patches, exploits, or active attacks.
