Charitable – Donation & Fundraising Platform (Donation Forms, Recurring Donations & Fundraising Campaigns) <= 1.8.11.3 - Missing Authorization
medium
The Charitable – Donation & Fundraising Platform (Donation Forms, Recurring Donations & Fundraising Campaigns) plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, 1.8.11.3. This is due to a missing capability check on a function. This makes it possible for unauthenticated att...
- CVSS:
- 5.3
- Affected:
- up to 1.8.11.3
- Fixed in:
- 1.8.12
- Disclosed:
- Aug 18, 2026
CVE-2026-73994 on NVD →
Charitable – Donation & Fundraising Platform (Donation Forms, Recurring Donations & Fundraising Campaigns) < 1.8.12 - Unauthenticated Donation Payment Bypass
medium
The Charitable – Donation & Fundraising Platform (Donation Forms, Recurring Donations & Fundraising Campaigns) plugin for WordPress is vulnerable to Payment Bypass in all versions up to 1.8.12 (exclusive). This makes it possible for unauthenticated attackers to bypass payments for donations.
- CVSS:
- 5.3
- Affected:
- up to 1.8.12
- Fixed in:
- 1.8.12
- Disclosed:
- Aug 14, 2026
CVE-2026-16650 on NVD →
Charitable – Donation & Fundraising Platform (Donation Forms, Recurring Donations & Fundraising Campaigns) < 1.8.5.3 - Authenticated (Administrator+) Stored Cross-Site Scripting
medium
The Charitable – Donation & Fundraising Platform (Donation Forms, Recurring Donations & Fundraising Campaigns) plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to 1.8.5.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with...
- CVSS:
- 4.4
- Affected:
- up to 1.8.5.3
- Fixed in:
- 1.8.5.3
- Disclosed:
- Aug 2, 2026
CVE-2025-15675 on NVD →
Charitable <= 1.8.11.1 - Authenticated (Subscriber+) Insecure Direct Object Reference to Arbitrary Attachment Deletion via 'avatar' Parameter
medium
The Charitable – Donation Plugin for WordPress – Fundraising with Recurring Donations & More plugin for WordPress is vulnerable to Insecure Direct Object Reference / Authorization Bypass leading to Arbitrary Attachment Deletion in versions up to, and including, 1.8.11.1 via the profile avatar update flow. This is due t...
- CVSS:
- 4.3
- Affected:
- up to 1.8.11.1
- Fixed in:
- 1.8.11.2
- Disclosed:
- Jun 5, 2026
CVE-2026-10038 on NVD →
Charitable <= 1.8.10.4 - Authenticated (Custom+) SQL Injection via 's' Search Parameter
medium
The Charitable – Donation Plugin for WordPress – Fundraising with Recurring Donations & More plugin for WordPress is vulnerable to generic SQL Injection via the 's' parameter in all versions up to, and including, 1.8.10.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on...
- CVSS:
- 6.5
- Affected:
- up to 1.8.10.4
- Fixed in:
- 1.8.10.5
- Disclosed:
- May 12, 2026
CVE-2026-7619 on NVD →
Charitable – Donation Plugin for WordPress – Fundraising with Recurring Donations & More <= 1.8.9.7 - Insufficient Verification of Data Authenticity to Unauthenticated Donation Status Forgery via Stripe Webhook
medium
The Charitable – Donation Plugin for WordPress – Fundraising with Recurring Donations & More plugin for WordPress is vulnerable to Insufficient Verification of Data Authenticity in versions up to, and including, 1.8.9.7. This is due to missing cryptographic verification of incoming Stripe webhook events. This makes it...
- CVSS:
- 5.3
- Affected:
- up to 1.8.9.7
- Fixed in:
- 1.8.10
- Disclosed:
- Apr 6, 2026
CVE-2026-3177 on NVD →
Charitable – Donation Plugin for WordPress – Fundraising with Recurring Donations & More [charitable] < 1.8.8.5
unknown
[en] The Charitable – Donation Plugin for WordPress – Fundraising with Recurring Donations & More plugin for WordPress is vulnerable to SQL Injection via the donation_ids parameter in all versions up to, and including, 1.8.8.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparatio...
- Affected:
- up to 1.8.8.5
- Fixed in:
- 1.8.8.5
- Disclosed:
- Oct 25, 2025
CVE-2025-11893 on NVD →
Charitable – Donation Plugin for WordPress – Fundraising with Recurring Donations & More <= 1.8.8.4 - Authenticated (Subscriber+) SQL Injection
medium
The Charitable – Donation Plugin for WordPress – Fundraising with Recurring Donations & More plugin for WordPress is vulnerable to SQL Injection via the donation_ids parameter in all versions up to, and including, 1.8.8.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on...
- CVSS:
- 6.5
- Affected:
- up to 1.8.8.4
- Fixed in:
- 1.8.8.5
- Disclosed:
- Oct 24, 2025
CVE-2025-11893 on NVD →
Charitable <= 1.8.6.1 - Authenticated (Administrator+) Stored Cross-Site Scripting via Plugin's Privacy Settings
medium
The Charitable – Donation Plugin for WordPress – Fundraising with Recurring Donations & More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the privacy settings fields in all versions up to, and including, 1.8.6.1 due to insufficient input sanitization and output escaping. This makes it possible...
- CVSS:
- 4.4
- Affected:
- up to 1.8.6.1
- Fixed in:
- 1.8.6.2
- Disclosed:
- Jun 25, 2025
CVE-2025-5275 on NVD →
Charitable <= 1.8.5.1 - Authenticated (Administrator+) Stored Cross-Site Scripting
medium
The Charitable plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.8.5.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access and above, to inject arbitrary web scripts in pages t...
- CVSS:
- 4.4
- Affected:
- up to 1.8.5.1
- Fixed in:
- 1.8.5.2
- Disclosed:
- May 7, 2025
CVE-2025-47520 on NVD →
Charitable – Donation Plugin for WordPress – Fundraising with Recurring Donations & More [charitable] < 1.8.5.2
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Syed Balkhi Charitable allows Stored XSS. This issue affects Charitable: from n/a through 1.8.5.1.
- Affected:
- up to 1.8.5.2
- Fixed in:
- 1.8.5.2
- Disclosed:
- May 7, 2025
CVE-2025-47520 on NVD →
Charitable – Donation Plugin for WordPress – Fundraising with Recurring Donations & More [charitable] < 1.8.4.8
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Syed Balkhi Charitable allows DOM-Based XSS. This issue affects Charitable: from n/a through 1.8.4.7.
- Affected:
- up to 1.8.4.8
- Fixed in:
- 1.8.4.8
- Disclosed:
- Mar 27, 2025
CVE-2025-30770 on NVD →
Charitable <= 1.8.4.7 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Charitable plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.8.4.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages tha...
- CVSS:
- 6.4
- Affected:
- up to 1.8.4.7
- Fixed in:
- 1.8.4.8
- Disclosed:
- Mar 26, 2025
CVE-2025-30770 on NVD →
Charitable – Donation Plugin for WordPress – Fundraising with Recurring Donations & More [charitable] < 1.8.3.1
unknown
[en] The Charitable – Donation Plugin for WordPress – Fundraising with Recurring Donations & More plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg & remove_query_arg without appropriate escaping on the URL in all versions up to, and including, 1.8.3. This makes it pos...
- Affected:
- up to 1.8.3.1
- Fixed in:
- 1.8.3.1
- Disclosed:
- Nov 9, 2024
CVE-2024-10876 on NVD →
Charitable – Donation Plugin for WordPress – Fundraising with Recurring Donations & More <= 1.8.3 - Reflected Cross-Site Scripting
medium
The Charitable – Donation Plugin for WordPress – Fundraising with Recurring Donations & More plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg & remove_query_arg without appropriate escaping on the URL in all versions up to, and including, 1.8.3. This makes it possible...
- CVSS:
- 6.1
- Affected:
- up to 1.8.3
- Fixed in:
- 1.8.3.1
- Disclosed:
- Nov 8, 2024
CVE-2024-10876 on NVD →
Charitable – Donation Plugin for WordPress – Fundraising with Recurring Donations & More [charitable] < 1.8.1.8
unknown
[en] Missing Authorization vulnerability in Charitable Donations & Fundraising Team Charitable allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Charitable: from n/a through 1.8.1.7.
- Affected:
- up to 1.8.1.8
- Fixed in:
- 1.8.1.8
- Disclosed:
- Nov 1, 2024
CVE-2024-37510 on NVD →
Charitable – Donation Plugin for WordPress – Fundraising with Recurring Donations & More [charitable] < 1.8.1.8
unknown
[en] Missing Authorization vulnerability in Charitable Donations & Fundraising Team Charitable allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Charitable: from n/a through 1.8.1.7.
- Affected:
- up to 1.8.1.8
- Fixed in:
- 1.8.1.8
- Disclosed:
- Nov 1, 2024
CVE-2024-37506 on NVD →
Charitable – Donation Plugin for WordPress – Fundraising with Recurring Donations & More [charitable] < 1.8.1.15
unknown
[en] The Donation Forms by Charitable – Donations Plugin & Fundraising Platform for WordPress plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.8.1.14. This is due to the plugin not properly verifying a user's identity when the ID parameter is supplied through the update...
- Affected:
- up to 1.8.1.15
- Fixed in:
- 1.8.1.15
- Disclosed:
- Sep 24, 2024
CVE-2024-8791 on NVD →
Donation Forms by Charitable – Donations Plugin & Fundraising Platform for WordPress <= 1.8.1.14 - Insecure Direct Object Reference to Account Takeover and Privilege Escalation
critical
The Donation Forms by Charitable – Donations Plugin & Fundraising Platform for WordPress plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.8.1.14. This is due to the plugin not properly verifying a user's identity when the ID parameter is supplied through the update_core...
- CVSS:
- 9.8
- Affected:
- up to 1.8.1.14
- Fixed in:
- 1.8.1.15
- Disclosed:
- Sep 23, 2024
CVE-2024-8791 on NVD →
Charitable <= 1.8.1.7 - Missing Authorization via ajax_license_check()
medium
The Charitable plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ajax_license_check function in versions up to, and including, 1.8.1.7. This makes it possible for unauthenticated attackers to verify a license.
- CVSS:
- 5.3
- Affected:
- up to 1.8.1.7
- Fixed in:
- 1.8.1.8
- Disclosed:
- Jul 4, 2024
CVE-2024-37510 on NVD →
Charitable <= 1.8.1.7 - Missing Authorization to Unauthorized Donation
medium
The Charitable plugin for WordPress is vulnerable to unauthorized access due to insufficient verification on the process_donation() function in versions up to, and including, 1.8.1.7. This makes it possible for unauthenticated attackers to donate on forms they shouldn't have access to.
- CVSS:
- 5.3
- Affected:
- up to 1.8.1.7
- Fixed in:
- 1.8.1.8
- Disclosed:
- Jul 4, 2024
CVE-2024-37506 on NVD →
Charitable – Donation Plugin for WordPress – Fundraising with Recurring Donations & More [charitable] < 1.7.0.14
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Charitable Donations & Fundraising Team Donation Forms by Charitable plugin <= 1.7.0.13 versions.
- Affected:
- up to 1.7.0.14
- Fixed in:
- 1.7.0.14
- Disclosed:
- Nov 22, 2023
CVE-2023-47816 on NVD →
Charitable <= 1.7.0.13 - Authenticated(Contributor+) Stored Cross-Site Scripting
medium
The Charitable plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in versions up to, and including, 1.7.0.13 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and...
- CVSS:
- 6.4
- Affected:
- up to 1.7.0.14
- Fixed in:
- 1.7.0.14
- Disclosed:
- Oct 11, 2023
CVE-2023-47816 on NVD →
Charitable – Donation Plugin for WordPress – Fundraising with Recurring Donations & More [charitable] < 1.7.0.14
unknown
The Charitable plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in versions up to, and including, 1.7.0.13 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and...
- Affected:
- up to 1.7.0.14
- Fixed in:
- 1.7.0.14
- Disclosed:
- Oct 11, 2023
Charitable – Donation Plugin for WordPress – Fundraising with Recurring Donations & More [charitable] < 1.7.0.13
unknown
[en] The Donation Forms by Charitable plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 1.7.0.12 due to insufficient restriction on the 'update_core_user' function. This makes it possible for unauthenticated attackers to specify their user role by supplying the 'role' paramete...
- Affected:
- up to 1.7.0.13
- Fixed in:
- 1.7.0.13
- Disclosed:
- Aug 23, 2023
CVE-2023-4404 on NVD →
Donation Forms by Charitable <= 1.7.0.12 - Unauthenticated Privilege Escalation
critical
The Donation Forms by Charitable plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 1.7.0.12 due to insufficient restriction on the 'update_core_user' function. This makes it possible for unauthenticated attackers to specify their user role by supplying the 'role' parameter dur...
- CVSS:
- 9.8
- Affected:
- up to 1.7.0.12
- Fixed in:
- 1.7.0.13
- Disclosed:
- Aug 17, 2023
CVE-2023-4404 on NVD →
Charitable – Donation Plugin for WordPress – Fundraising with Recurring Donations & More [charitable] < 1.7.0.11
unknown
[en] Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Charitable Donations & Fundraising Team Donation Forms by Charitable plugin <= 1.7.0.10 versions.
- Affected:
- up to 1.7.0.11
- Fixed in:
- 1.7.0.11
- Disclosed:
- May 10, 2023
CVE-2022-47441 on NVD →
Charitable <= 1.7.0.10 - Reflected Cross-Site Scripting
medium
The Charitable plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.7.0.10 due to insufficient input sanitization and output escaping on the 'start_date_from', 'start_date_to', 'end_date_from', and 'end_date_to' parameters. This makes it possible for unauthenticated a...
- CVSS:
- 6.1
- Affected:
- up to 1.7.0.10
- Fixed in:
- 1.7.0.11
- Disclosed:
- Apr 19, 2023
CVE-2022-47441 on NVD →
Charitable – Donation Plugin for WordPress – Fundraising with Recurring Donations & More [charitable] < 1.6.51
unknown
[en] The Charitable – Donation Plugin WordPress plugin before 1.6.51 is affected by an authenticated stored cross-site scripting vulnerability which was found in the add donation feature.
- Affected:
- up to 1.6.51
- Fixed in:
- 1.6.51
- Disclosed:
- Aug 23, 2021
CVE-2021-24531 on NVD →
Charitable – Donation Plugin <= 1.6.50 - Unauthenticated Stored Cross-Site Scripting
high
The Charitable – Donation Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.6.50 due to insufficient input sanitization and output escaping on the 'first_name' parameter. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pa...
- CVSS:
- 7.2
- Affected:
- up to 1.6.50
- Fixed in:
- 1.6.51
- Disclosed:
- Jul 21, 2021
Charitable – Donation Plugin <= 1.6.50 - Authenticated Stored Cross-Site Scripting
medium
The Charitable – Donation Plugin WordPress plugin before 1.6.51 is affected by an authenticated stored cross-site scripting vulnerability which was found in the add donation feature.
- CVSS:
- 6.4
- Affected:
- up to 1.6.50
- Fixed in:
- 1.6.51
- Disclosed:
- Jul 21, 2021
CVE-2021-24531 on NVD →
Charitable – Donation Plugin for WordPress – Fundraising with Recurring Donations & More [charitable] < 1.6.51
unknown
Unauthenticated Stored Cross-Site Scripting (XSS) vulnerability discovered by Eric Daams in WordPress Charitable plugin (versions <= 1.6.50).
- Affected:
- up to 1.6.51
- Fixed in:
- 1.6.51
- Disclosed:
- Jul 21, 2021
Charitable – Donation Plugin for WordPress – Fundraising with Recurring Donations & More [charitable] < 1.6.51
unknown
The Charitable – Donation Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.6.50 due to insufficient input sanitization and output escaping on the 'first_name' parameter. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pa...
- Affected:
- up to 1.6.51
- Fixed in:
- 1.6.51
- Disclosed:
- Jul 21, 2021
Charitable – Donation Plugin for WordPress – Fundraising with Recurring Donations & More [charitable] < 1.5.14
unknown
[en] The charitable plugin before 1.5.14 for WordPress has unauthorized access to user and donation details.
- Affected:
- up to 1.5.14
- Fixed in:
- 1.5.14
- Disclosed:
- Sep 9, 2019
CVE-2018-21011 on NVD →
Charitable <= 1.5.13 - Unauthorized Access to Information Disclosure
medium
The charitable plugin before 1.5.14 for WordPress has unauthorized access to user and donation details.
- CVSS:
- 5.3
- Affected:
- up to 1.5.14
- Fixed in:
- 1.5.14
- Disclosed:
- May 16, 2018
CVE-2018-21011 on NVD →
Charitable – Donation Plugin for WordPress – Fundraising with Recurring Donations & More [charitable] < 1.8.6.2
unknown
- Affected:
- up to 1.8.6.2
- Fixed in:
- 1.8.6.2
CVE-2025-5275 on NVD →
Charitable – Donation Plugin for WordPress – Fundraising with Recurring Donations & More [charitable] < 1.6.51
unknown
While fixing an Authenticated Stored Cross-Site Scripting issue (https://wpscan.com/vulnerability/a5837621-ee6e-4876-9f65-82658fc0341f), the vendor identified another Cross-Site Scripting issue, which could be exploited by unauthenticated users and would be triggered in the context of a logged in admin
- Affected:
- up to 1.6.51
- Fixed in:
- 1.6.51