Lucene search

K
wpvulndbWpvulndbWPVDB-ID:AEED2E60-CDF2-42FE-B1CB-13BB777D196B
HistoryNov 17, 2023 - 12:00 a.m.

Donations Made Easy - Smart Donations <= 4.0.12 - Stored XSS via CSRF

2023-11-1700:00:00
wpscan.com
5
donations
csrf
sanitisation
escaping
xss payload
contributor

6 Medium

AI Score

Confidence

High

0.0005 Low

EPSS

Percentile

17.0%

Description The plugin does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in Contributor add Stored XSS payloads via a CSRF attack

6 Medium

AI Score

Confidence

High

0.0005 Low

EPSS

Percentile

17.0%

Related for WPVDB-ID:AEED2E60-CDF2-42FE-B1CB-13BB777D196B