PT-2026-67001 · WordPress · Charitable
CVSS v3.1
4.8
Medium
| Vector | AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Charitable WordPress plugin versions prior to 1.8.5.3
Description
Stored Cross-Site Scripting (XSS) occurs because a campaign image text field is not properly sanitized and escaped before being output in an HTML attribute. This allows users with a high-privilege campaign-management role to execute malicious scripts on the front-end campaign page.
Recommendations
Update the Charitable WordPress plugin to version 1.8.5.3 or later.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Charitable