An expert found a Stored XSS vulnerability that affects the SecurePayment page directly which allowed me to alter the page HTML and rewrite the page content. An attacker can provide his own HTML forms to the user to fulfill and send the users data back to the server in clear text format, and then use this information to purchase anything in behave of users or even transfer the users fund to his own account! wrote the expert in a blog post. The expert ethically reported the flaw to Paypal that promptly fixed it, this is the Time Line of the bug:”]
Source: https://securityaffairs.co/wordpress/39606/hacking/paypal-critical-flaw.html