• PayPal checkout in this plugin completely ignores required fields in the order window (done via aircheckout), ignores captcha and virtually only checks for “terms and conditions” checkbox, opening the site to potential fraudsters.

Viewing 1 replies (of 1 total)
  • Plugin Author Payment Plugins

    (@mrclayton)

    Hi @bossman1282

    PayPal checkout in this plugin completely ignores required fields in the order window (done via aircheckout),

    Billing and Shipping fields don’t need to be validated because the PayPal plugin has the ability to provide those values automatically. Why would you expect your customers to enter information twice when PayPal can provide it automatically?

    ignores captcha and virtually only checks for “terms and conditions” checkbox, opening the site to potential fraudsters.

    This plugin doesn’t open the site up to fraud, that’s not how reCAPTCHA or carding attacks work. PayPal is an authenticated payment method, meaning you have to login to to your PayPal account before a payment can be processed. The order could never be processed unless the customer first logged in to their PayPal account and authenticated.

    It would be nice if users like yourself that benefit from free solutions would open a support ticket with these questions so we could address them rather than immediately leaving a one star review. Pretty disappointing and shows a lack of respect for the time and effort required to maintain a solution of such high quality, all for free.

    Kind Regards,

Viewing 1 replies (of 1 total)
  • The topic ‘critical security flaws in the plugin’ is closed to new replies.