Show filters
9 Total Results
Displaying 1-9 of 9
Sort by:
Attacker Value
Unknown
CVE-2024-10876
Disclosure Date: November 09, 2024 (last updated November 09, 2024)
The Charitable – Donation Plugin for WordPress – Fundraising with Recurring Donations & More plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg & remove_query_arg without appropriate escaping on the URL in all versions up to, and including, 1.8.3. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
0
Attacker Value
Unknown
CVE-2024-37510
Disclosure Date: November 01, 2024 (last updated November 02, 2024)
Missing Authorization vulnerability in Charitable Donations & Fundraising Team Charitable allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Charitable: from n/a through 1.8.1.7.
0
Attacker Value
Unknown
CVE-2024-37506
Disclosure Date: November 01, 2024 (last updated November 02, 2024)
Missing Authorization vulnerability in Charitable Donations & Fundraising Team Charitable allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Charitable: from n/a through 1.8.1.7.
0
Attacker Value
Unknown
CVE-2024-8791
Disclosure Date: September 24, 2024 (last updated September 27, 2024)
The Donation Forms by Charitable – Donations Plugin & Fundraising Platform for WordPress plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.8.1.14. This is due to the plugin not properly verifying a user's identity when the ID parameter is supplied through the update_core_user() function. This makes it possible for unauthenticated attackers to update the email address and password of arbitrary user accounts, including administrators, which can then be used to log in to those user accounts.
0
Attacker Value
Unknown
CVE-2023-47816
Disclosure Date: November 22, 2023 (last updated November 29, 2023)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Charitable Donations & Fundraising Team Donation Forms by Charitable plugin <= 1.7.0.13 versions.
0
Attacker Value
Unknown
CVE-2023-4404
Disclosure Date: August 23, 2023 (last updated February 25, 2025)
The Donation Forms by Charitable plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 1.7.0.12 due to insufficient restriction on the 'update_core_user' function. This makes it possible for unauthenticated attackers to specify their user role by supplying the 'role' parameter during a registration.
0
Attacker Value
Unknown
CVE-2022-47441
Disclosure Date: May 10, 2023 (last updated February 24, 2025)
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Charitable Donations & Fundraising Team Donation Forms by Charitable plugin <= 1.7.0.10 versions.
0
Attacker Value
Unknown
CVE-2021-24531
Disclosure Date: August 23, 2021 (last updated February 23, 2025)
The Charitable – Donation Plugin WordPress plugin before 1.6.51 is affected by an authenticated stored cross-site scripting vulnerability which was found in the add donation feature.
0
Attacker Value
Unknown
CVE-2018-21011
Disclosure Date: September 09, 2019 (last updated November 27, 2024)
The charitable plugin before 1.5.14 for WordPress has unauthorized access to user and donation details.
0