wpcharitable records
8 published records for vendor wpcharitable.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 50%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')3
- CWE-862 Missing Authorization2
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-269 Improper Privilege Management1
- CWE-639 Authorization Bypass Through User-Controlled Key1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
8 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
39Monitor | CVE-2023-4404No exploit | Donation Forms by Charitable <= 1.7.0.12 - Unauthenticated Privilege Escalationwpcharitable · charitable · CWE-269 | Critical9.8 | — | 0.9% | Aug 22, 2023 |
39Monitor | CVE-2024-8791No exploit | Donation Forms by Charitable – Donations Plugin & Fundraising Platform for WordPress <= 1.8.1.14 - Insecure Direct Object Reference to Account Takeover and Privwpcharitable · charitable · CWE-639 | Critical9.8 | — | 0.7% | Sep 23, 2024 |
31Monitor | CVE-2018-21011No exploit | The charitable plugin before 1.5.14 for WordPress has unauthorized access to user and donation details.wpcharitable · charitable · CWE-200 | High7.5 | — | 1.7% | Sep 9, 2019 |
26Monitor | CVE-2024-37510No exploit | WordPress Donation Forms by Charitable plugin <= 1.8.1.7 - Broken Access Control vulnerabilitycharitable donations & fundraising team · charitable · CWE-862 | Medium6.5 | — | 0.5% | Nov 1, 2024 |
24Monitor | CVE-2022-47441No exploit | WordPress Charitable Plugin <= 1.7.0.10 is vulnerable to Cross Site Scripting (XSS)wpcharitable · charitable · CWE-79 | Medium6.1 | — | 0.4% | May 10, 2023 |
21Monitor | CVE-2021-24531No exploit | Charitable – Donation Plugin < 1.6.51 - Authenticated Stored Cross-Site Scripting (XSS)wpcharitable · charitable · CWE-79 | Medium5.4 | — | 0.6% | Aug 23, 2021 |
21Monitor | CVE-2023-47816No exploit | WordPress Charitable Plugin <= 1.7.0.13 is vulnerable to Cross Site Scripting (XSS)wpcharitable · charitable · CWE-79 | Medium5.4 | — | 0.4% | Nov 22, 2023 |
21Monitor | CVE-2024-37506No exploit | WordPress Donation Forms by Charitable plugin <= 1.8.1.7 - Broken Access Control vulnerabilitycharitable donations & fundraising team · charitable · CWE-862 | Medium5.3 | — | 0.4% | Nov 1, 2024 |
- CVE-2023-440439Monitor
Donation Forms by Charitable <= 1.7.0.12 - Unauthenticated Privilege Escalation
CriticalCVSS 9.8No exploitEPSS 1%wpcharitable · charitableAug 22, 2023
- CVE-2024-879139Monitor
Donation Forms by Charitable – Donations Plugin & Fundraising Platform for WordPress <= 1.8.1.14 - Insecure Direct Object Reference to Account Takeover and Priv
CriticalCVSS 9.8No exploitEPSS 1%wpcharitable · charitableSep 23, 2024
- CVE-2018-2101131Monitor
The charitable plugin before 1.5.14 for WordPress has unauthorized access to user and donation details.
HighCVSS 7.5No exploitEPSS 2%wpcharitable · charitableSep 9, 2019
- CVE-2024-3751026Monitor
WordPress Donation Forms by Charitable plugin <= 1.8.1.7 - Broken Access Control vulnerability
MediumCVSS 6.5No exploitEPSS 0%charitable donations & fundraising team · charitableNov 1, 2024
- CVE-2022-4744124Monitor
WordPress Charitable Plugin <= 1.7.0.10 is vulnerable to Cross Site Scripting (XSS)
MediumCVSS 6.1No exploitEPSS 0%wpcharitable · charitableMay 10, 2023
- CVE-2021-2453121Monitor
Charitable – Donation Plugin < 1.6.51 - Authenticated Stored Cross-Site Scripting (XSS)
MediumCVSS 5.4No exploitEPSS 1%wpcharitable · charitableAug 23, 2021
- CVE-2023-4781621Monitor
WordPress Charitable Plugin <= 1.7.0.13 is vulnerable to Cross Site Scripting (XSS)
MediumCVSS 5.4No exploitEPSS 0%wpcharitable · charitableNov 22, 2023
- CVE-2024-3750621Monitor
WordPress Donation Forms by Charitable plugin <= 1.8.1.7 - Broken Access Control vulnerability
MediumCVSS 5.3No exploitEPSS 0%charitable donations & fundraising team · charitableNov 1, 2024