CVE-2024-30527

HIGH

Tips and Tricks HQ WP Express Checkout <2.3.7 - Info Disclosure

Title source: llm
STIX 2.1

Description

Improper Validation of Specified Quantity in Input vulnerability in Tips and Tricks HQ WP Express Checkout (Accept PayPal Payments) allows Manipulating Hidden Fields.This issue affects WP Express Checkout (Accept PayPal Payments): from n/a through 2.3.7.

Scores

CVSS v3 7.5
EPSS 0.0051
EPSS Percentile 66.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-1284
Status published
Products (1)
Tips and Tricks HQ/WP Express Checkout (Accept PayPal Payments) < 2.3.7
Published May 17, 2024
Tracked Since Feb 18, 2026