CVE-2020-25750: Dotplant DOTPLANT2

High severity, CVSS 7.5. EPSS: 1.1% chance of exploitation in the next 30 days.

An issue was discovered in DotPlant2 before 2020-09-14. In class Pay2PayPayment in payment/Pay2PayPayment.php, there is an XXE vulnerability in the checkResult function. The user input ($_POST['xml']) is used for simplexml_load_string without sanitization. NOTE: This vulnerability only affects products that are no longer supported by the maintainer

Affected products

  • Dotplant DOTPLANT2: before 2020-09-14 (fixed in 2020-09-14)

Published 2020-09-18. Last modified 2026-06-17.