cleantalk
Vulnerabilities and Security Researches

Donation Forms by Charitable – Donations Plugin & Fundraising Platform for WordPress, CVE-2025-47520

CVE, Research URL

CVE-2025-47520

Published on
May 07, 2025
Research Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Syed Balkhi Charitable allows Stored XSS. This issue affects Charitable: from n/a through 1.8.5.1.
Affected versions
Min -, max 1.8.5.2.
Status
vulnerable