WordPress security by component
Charitable
Plugin description
Charitable is a WordPress component with 16 published CVE records in this archive. The latest tracked vulnerability was published Aug 02, 2026; the highest published CVSS base score is 9.8.
Plugin slug:
charitableLatest vulnerability
CVE-2025-15675: Charitable campaign image text lets managers store JavaScript
Charitable before 1.8.5.3 does not sanitize and escape a campaign-image text field before inserting it into an HTML attribute on the public campaign page. A user holding a high-privilege campaign-management role can break out of the attribute and store JavaScript that executes for front-end visitors. The CNA record does not disclose the field, save action, role capability or renderer.
| Safe version |
|
||
|---|---|---|---|
| Aug 02, 2026 |
CVE-2025-15675
Charitable campaign image text lets managers store JavaScript
Charitable before 1.8.5.3 does not sanitize and escape a campaign-image text field before inserting it into an HTML attribute on the public campaign page. A user holding a high-privilege campaign-management role can break out of the attribute and store JavaScript that executes for front-end visitors. The CNA record does not disclose the field, save action, role capability or renderer.
|
1.8.5.3 |
CVE4.8
NVDPending
|
| Jun 06, 2026 |
CVE-2026-10038
Charitable – Donation Plugin for WordPress – Fundraising with Recurring Donations & More: Broken access control
Charitable – Donation Plugin for WordPress – Fundraising with Recurring Donations & More is affected by broken access control. Exploitation requires an authenticated subscriber account. A successful request can reach data or an operation that should be restricted to another user or a more privileged role. The published affected range is <= 1.8.11.1. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
See mitigation notes |
CVE4.3
NVDPending
|
| May 13, 2026 |
CVE-2026-7619
Charitable – Donation Plugin for WordPress – Fundraising with Recurring Donations & More: SQL injection
Charitable – Donation Plugin for WordPress – Fundraising with Recurring Donations & More is affected by SQL injection. Exploitation requires an authenticated WordPress account. A successful request can alter database queries and expose or modify WordPress data. The published affected range is <= 1.8.10.4. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
See mitigation notes |
CVE6.5
NVDPending
|
| Oct 25, 2025 |
CVE-2025-11893
Charitable – Donation: SQL injection
Charitable – Donation is affected by SQL injection. Exploitation requires an authenticated subscriber account. A successful request can alter database queries and expose or modify WordPress data. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
See mitigation notes |
CVE6.5
NVDPending
|
| Jun 26, 2025 |
CVE-2025-5275
Charitable – Donation: Cross-site scripting
Charitable – Donation is affected by cross-site scripting. Exploitation requires an authenticated administrator account. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
See mitigation notes |
CVE4.4
NVD4.0
|
| May 07, 2025 |
CVE-2025-47520
Charitable: Cross-site scripting
Charitable is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
See mitigation notes |
CVE5.9
NVDPending
|
| Mar 27, 2025 |
CVE-2025-30770
Charitable: Cross-site scripting
Charitable is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
See mitigation notes |
CVE6.5
NVDPending
|
| Nov 09, 2024 |
CVE-2024-10876
Charitable – Donation: Cross-site scripting
Charitable – Donation is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
See mitigation notes |
CVE6.1
NVDPending
|
| Nov 01, 2024 |
CVE-2024-37510
Charitable: A security weakness
Charitable is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
See mitigation notes |
CVE6.5
NVDPending
|
| Nov 01, 2024 |
CVE-2024-37506
Charitable: A security weakness
Charitable is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
See mitigation notes |
CVE5.3
NVDPending
|
| Sep 24, 2024 |
CVE-2024-8791
Donation Forms by Charitable – Donations Plugin & Fundraising Platform for: Privilege escalation or authentication bypass
Donation Forms by Charitable – Donations Plugin & Fundraising Platform for is affected by privilege escalation or authentication bypass. The vulnerable path is reachable without authentication. A successful request can grant permissions or access that the caller should not possess. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
See mitigation notes |
CVE9.8
NVDPending
|
| Nov 22, 2023 |
CVE-2023-47816
Charitable: Cross-site scripting
Charitable is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
See mitigation notes |
CVE6.5
NVD5.4
|
| Aug 23, 2023 |
CVE-2023-4404
Donation Forms by Charitable: Privilege escalation or authentication bypass
Donation Forms by Charitable is affected by privilege escalation or authentication bypass. The vulnerable path is reachable without authentication. A successful request can grant permissions or access that the caller should not possess. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
See mitigation notes |
CVE9.8
NVD9.8
|
| May 10, 2023 |
CVE-2022-47441
Charitable: Cross-site scripting
Charitable is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
See mitigation notes |
CVE7.1
NVD6.1
|
| Aug 23, 2021 |
CVE-2021-24531
Charitable – Donation Plugin: Cross-site scripting
Charitable – Donation Plugin is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
See mitigation notes |
CVEPending
NVD5.4
|
| Sep 09, 2019 |
CVE-2018-21011
Charitable: A security weakness
Charitable is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
See mitigation notes |
CVEPending
NVD7.5
|