Vulnerability record · CVE-2020-14092 · published 2 July 2020
CVE-2020-14092: WordPress Payment Form for PayPal Pro plugin SQL injection
Ithemes · Paypal Pro
The CodePeople Payment Form for PayPal Pro plugin for WordPress before version 1.1.65 is vulnerable to SQL injection. The flaw is remotely reachable without authentication, so any exposed installation running an older version can be attacked directly.
Description
The CodePeople Payment Form for PayPal Pro plugin before 1.1.65 for WordPress allows SQL Injection.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 with no authentication or user interaction required and a very high EPSS score make this a high-impact, remotely exploitable SQL injection.
What it is
The CodePeople Payment Form for PayPal Pro plugin for WordPress before version 1.1.65 is vulnerable to SQL injection. The flaw is remotely reachable without authentication, so any exposed installation running an older version can be attacked directly.
Impact
An attacker can inject arbitrary SQL into the plugin's database queries, potentially reading, altering or deleting data and, depending on database privileges, executing further database-level actions.
Attack surface
Reached over the network via the WordPress plugin's request handling; the CVSS vector indicates no privileges and no user interaction are required. The description does not identify the specific vulnerable parameter or endpoint.
Exploitation
Not listed in CISA KEV and no public exploit reference is tagged in the record, but EPSS is very high (0.9453, 99.8th percentile), indicating elevated likelihood of attempted exploitation.
What to do
- Update the Payment Form for PayPal Pro plugin to version 1.1.65 or later.
- If patching is not immediately possible, disable or remove the plugin until it can be updated.
- Restrict access to the WordPress admin and plugin endpoints via WAF or IP allowlisting where feasible.
- Review database accounts used by WordPress for least privilege to limit the impact of successful injection.
- Audit the site for signs of prior compromise, including unexpected database changes or admin accounts.
Detection
- Monitor web server and WAF logs for SQL metacharacters or injection patterns in requests to the plugin's endpoints.
- Alert on unexpected database errors or anomalous query behavior originating from the web application.
- Review database and file integrity for unauthorized changes on hosts running the plugin.
- Check installed plugin versions against 1.1.65 to identify exposed instances.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://wordpress.dwbooster.com/forms/payment-form-for-paypal-pro | Product |
| https://wordpress.org/plugins/payment-form-for-paypal-pro/#developers | Release NotesThird Party Advisory |
| https://wpvulndb.com/vulnerabilities/10287 | Third Party Advisory |
| https://wordpress.dwbooster.com/forms/payment-form-for-paypal-pro | Product |
| https://wordpress.org/plugins/payment-form-for-paypal-pro/#developers | Release NotesThird Party Advisory |
| https://wpvulndb.com/vulnerabilities/10287 | Third Party Advisory |
Track CVE-2020-14092 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2020-14092), CISA KEV, FIRST EPSS (scores of 2026-09-23). This page is refreshed as NVD updates the record.