Donation Forms by Charitable – Donations Plugin & Fundraising Platform for WordPress, 06f5a9afc827d55a7b534502be1c4d0be2eb6055
- CVE, Research URL
- Home page URL
- Application
-
Donation Forms by Charitable – Donations Plugin & Fundraising Platform for WordPress
- Published on
- Jul 21, 2021
- Research Description
- Charitable – Donation Plugin for WordPress – Fundraising with Recurring Donations & More [charitable] < 1.6.51 Charitable – Donation Plugin <= 1.6.50 - Unauthenticated Stored Cross-Site Scripting The Charitable – Donation Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.6.50 due to insufficient input sanitization and output escaping on the 'first_name' parameter. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
- Affected versions
-
max 1.6.51.
- Status
-
vulnerable