VendorsWPCharitablecharitableany version
Vulnerabilities

WPCharitable Charitable any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

6CVEs
CVE-2023-4404
Donation Forms by Charitable <= 1.7.0.12 - Unauthenticated Privilege Escalation
Published 2023-08-23 · Modified
9.8EPSS 0.009
CVE-2024-8791
Donation Forms by Charitable – Donations Plugin & Fundraising Platform for WordPress <= 1.8.1.14 - Insecure Direct Object Reference to Account Takeover and Privilege Escalation
Published 2024-09-24 · Analyzed
9.8EPSS 0.007
CVE-2018-21011
The charitable plugin before 1.5.14 for WordPress has unauthorized access to user and donation details.
Published 2019-09-09 · Modified
7.5EPSS 0.017
CVE-2022-47441
WordPress Charitable Plugin <= 1.7.0.10 is vulnerable to Cross Site Scripting (XSS)
Published 2023-05-10 · Modified
7.1EPSS 0.004
CVE-2023-47816
WordPress Charitable Plugin <= 1.7.0.13 is vulnerable to Cross Site Scripting (XSS)
Published 2023-11-22 · Modified
6.5EPSS 0.004
CVE-2021-24531
Charitable – Donation Plugin < 1.6.51 - Authenticated Stored Cross-Site Scripting (XSS)
Published 2021-08-23 · Modified
5.4EPSS 0.006