wpcharitable charitable CVE Vulnerabilities (6)

CVEs: 6 CPE versions: View versions table

Summary

This page lists publicly disclosed CVE vulnerabilities affecting wpcharitable charitable (linked via NVD CPE). Each row includes severity scores, summaries, and publication dates to help identify and analyze security issues.

Showing 16 of 6 CVEs
«« First « Prev Page 1 / 1 Next »
CVE Summary Source Max CVSS EPSS % Published Updated
CVE-2024-8791 The Donation Forms by Charitable – Donations Plugin & Fundraising Platform for WordPress plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.8.1.14. This is due to the plugin not properly verifying a user's identity when the ID parameter is supplied through the update_core_user() function. This makes it possible for unauthenticated attackers to update the email address and password of arbitrary user accounts, including administrators, which can then [email protected] 9.8 0.29% 2024-09-24 2024-09-26
CVE-2023-47816 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Charitable Donations & Fundraising Team Donation Forms by Charitable plugin <= 1.7.0.13 versions. [email protected] 6.5 0.08% 2023-11-22 2024-11-21
CVE-2023-4404 The Donation Forms by Charitable plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 1.7.0.12 due to insufficient restriction on the 'update_core_user' function. This makes it possible for unauthenticated attackers to specify their user role by supplying the 'role' parameter during a registration. [email protected] 9.8 0.30% 2023-08-23 2026-04-08
CVE-2022-47441 Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Charitable Donations & Fundraising Team Donation Forms by Charitable plugin <= 1.7.0.10 versions. [email protected] 7.1 0.29% 2023-05-10 2024-11-21
CVE-2021-24531 The Charitable – Donation Plugin WordPress plugin before 1.6.51 is affected by an authenticated stored cross-site scripting vulnerability which was found in the add donation feature. [email protected] 5.4 0.53% 2021-08-23 2024-11-21
CVE-2018-21011 The charitable plugin before 1.5.14 for WordPress has unauthorized access to user and donation details. [email protected] 7.5 0.75% 2019-09-09 2024-11-21
«« First « Prev Page 1 / 1 Next »
cvelogic Threat Intelligence