Skip to content
Noroxi

wpcharitable records

8 published records for vendor wpcharitable.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
0
With a fix record
50%
Median publish → KEV
No record has entered KEV

All records

8 records
  • CVE-2023-4404
    39Monitor

    Donation Forms by Charitable <= 1.7.0.12 - Unauthenticated Privilege Escalation

    CriticalCVSS 9.8No exploitEPSS 1%

    wpcharitable · charitableAug 22, 2023

  • CVE-2024-8791
    39Monitor

    Donation Forms by Charitable – Donations Plugin & Fundraising Platform for WordPress <= 1.8.1.14 - Insecure Direct Object Reference to Account Takeover and Priv

    CriticalCVSS 9.8No exploitEPSS 1%

    wpcharitable · charitableSep 23, 2024

  • The charitable plugin before 1.5.14 for WordPress has unauthorized access to user and donation details.

    HighCVSS 7.5No exploitEPSS 2%

    wpcharitable · charitableSep 9, 2019

  • WordPress Donation Forms by Charitable plugin <= 1.8.1.7 - Broken Access Control vulnerability

    MediumCVSS 6.5No exploitEPSS 0%

    charitable donations & fundraising team · charitableNov 1, 2024

  • WordPress Charitable Plugin <= 1.7.0.10 is vulnerable to Cross Site Scripting (XSS)

    MediumCVSS 6.1No exploitEPSS 0%

    wpcharitable · charitableMay 10, 2023

  • Charitable – Donation Plugin < 1.6.51 - Authenticated Stored Cross-Site Scripting (XSS)

    MediumCVSS 5.4No exploitEPSS 1%

    wpcharitable · charitableAug 23, 2021

  • WordPress Charitable Plugin <= 1.7.0.13 is vulnerable to Cross Site Scripting (XSS)

    MediumCVSS 5.4No exploitEPSS 0%

    wpcharitable · charitableNov 22, 2023

  • WordPress Donation Forms by Charitable plugin <= 1.8.1.7 - Broken Access Control vulnerability

    MediumCVSS 5.3No exploitEPSS 0%

    charitable donations & fundraising team · charitableNov 1, 2024