Donation Forms by Charitable – Donations Plugin & Fundraising Platform for WordPress, CVE-2025-15675
- CVE, Research URL
- Home page URL
- Application
-
Donation Forms by Charitable – Donations Plugin & Fundraising Platform for WordPress
- Published on
- Aug 02, 2026
- Research Description
- The Charitable WordPress plugin before 1.8.5.3 does not sanitise and escape one of its campaign image text fields before outputting it in an HTML attribute, allowing users with a high-privilege campaign-management role to perform Stored Cross-Site Scripting attacks that execute on the front-end campaign page.
- Affected versions
-
max 1.8.5.3.
- Status
-
vulnerable