plugin

Charitable Vulnerabilities

37 known security issues reported for the Charitable WordPress plugin. Most recent disclosed Aug 18, 2026.

2 critical 1 high 17 medium

Running Charitable on your site? Check whether your installed version is affected.

Scan your site free

Charitable – Donation & Fundraising Platform (Donation Forms, Recurring Donations & Fundraising Campaigns) <= 1.8.11.3 - Missing Authorization

medium

The Charitable – Donation & Fundraising Platform (Donation Forms, Recurring Donations & Fundraising Campaigns) plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, 1.8.11.3. This is due to a missing capability check on a function. This makes it possible for unauthenticated att...

CVSS:
5.3
Affected:
up to 1.8.11.3
Fixed in:
1.8.12
Disclosed:
Aug 18, 2026

CVE-2026-73994 on NVD →

Charitable – Donation & Fundraising Platform (Donation Forms, Recurring Donations & Fundraising Campaigns) < 1.8.12 - Unauthenticated Donation Payment Bypass

medium

The Charitable – Donation & Fundraising Platform (Donation Forms, Recurring Donations & Fundraising Campaigns) plugin for WordPress is vulnerable to Payment Bypass in all versions up to 1.8.12 (exclusive). This makes it possible for unauthenticated attackers to bypass payments for donations.

CVSS:
5.3
Affected:
up to 1.8.12
Fixed in:
1.8.12
Disclosed:
Aug 14, 2026

CVE-2026-16650 on NVD →

Charitable – Donation & Fundraising Platform (Donation Forms, Recurring Donations & Fundraising Campaigns) < 1.8.5.3 - Authenticated (Administrator+) Stored Cross-Site Scripting

medium

The Charitable – Donation & Fundraising Platform (Donation Forms, Recurring Donations & Fundraising Campaigns) plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to 1.8.5.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with...

CVSS:
4.4
Affected:
up to 1.8.5.3
Fixed in:
1.8.5.3
Disclosed:
Aug 2, 2026

CVE-2025-15675 on NVD →

Charitable <= 1.8.11.1 - Authenticated (Subscriber+) Insecure Direct Object Reference to Arbitrary Attachment Deletion via 'avatar' Parameter

medium

The Charitable – Donation Plugin for WordPress – Fundraising with Recurring Donations & More plugin for WordPress is vulnerable to Insecure Direct Object Reference / Authorization Bypass leading to Arbitrary Attachment Deletion in versions up to, and including, 1.8.11.1 via the profile avatar update flow. This is due t...

CVSS:
4.3
Affected:
up to 1.8.11.1
Fixed in:
1.8.11.2
Disclosed:
Jun 5, 2026

CVE-2026-10038 on NVD →

Charitable <= 1.8.10.4 - Authenticated (Custom+) SQL Injection via 's' Search Parameter

medium

The Charitable – Donation Plugin for WordPress – Fundraising with Recurring Donations & More plugin for WordPress is vulnerable to generic SQL Injection via the 's' parameter in all versions up to, and including, 1.8.10.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on...

CVSS:
6.5
Affected:
up to 1.8.10.4
Fixed in:
1.8.10.5
Disclosed:
May 12, 2026

CVE-2026-7619 on NVD →

Charitable – Donation Plugin for WordPress – Fundraising with Recurring Donations & More <= 1.8.9.7 - Insufficient Verification of Data Authenticity to Unauthenticated Donation Status Forgery via Stripe Webhook

medium

The Charitable – Donation Plugin for WordPress – Fundraising with Recurring Donations & More plugin for WordPress is vulnerable to Insufficient Verification of Data Authenticity in versions up to, and including, 1.8.9.7. This is due to missing cryptographic verification of incoming Stripe webhook events. This makes it...

CVSS:
5.3
Affected:
up to 1.8.9.7
Fixed in:
1.8.10
Disclosed:
Apr 6, 2026

CVE-2026-3177 on NVD →

Charitable &#8211; Donation Plugin for WordPress &#8211; Fundraising with Recurring Donations &amp; More [charitable] < 1.8.8.5

unknown

[en] The Charitable – Donation Plugin for WordPress – Fundraising with Recurring Donations & More plugin for WordPress is vulnerable to SQL Injection via the donation_ids parameter in all versions up to, and including, 1.8.8.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparatio...

Affected:
up to 1.8.8.5
Fixed in:
1.8.8.5
Disclosed:
Oct 25, 2025

CVE-2025-11893 on NVD →

Charitable – Donation Plugin for WordPress – Fundraising with Recurring Donations & More <= 1.8.8.4 - Authenticated (Subscriber+) SQL Injection

medium

The Charitable – Donation Plugin for WordPress – Fundraising with Recurring Donations & More plugin for WordPress is vulnerable to SQL Injection via the donation_ids parameter in all versions up to, and including, 1.8.8.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on...

CVSS:
6.5
Affected:
up to 1.8.8.4
Fixed in:
1.8.8.5
Disclosed:
Oct 24, 2025

CVE-2025-11893 on NVD →

Charitable <= 1.8.6.1 - Authenticated (Administrator+) Stored Cross-Site Scripting via Plugin's Privacy Settings

medium

The Charitable – Donation Plugin for WordPress – Fundraising with Recurring Donations & More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the privacy settings fields in all versions up to, and including, 1.8.6.1 due to insufficient input sanitization and output escaping. This makes it possible...

CVSS:
4.4
Affected:
up to 1.8.6.1
Fixed in:
1.8.6.2
Disclosed:
Jun 25, 2025

CVE-2025-5275 on NVD →

Charitable <= 1.8.5.1 - Authenticated (Administrator+) Stored Cross-Site Scripting

medium

The Charitable plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.8.5.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access and above, to inject arbitrary web scripts in pages t...

CVSS:
4.4
Affected:
up to 1.8.5.1
Fixed in:
1.8.5.2
Disclosed:
May 7, 2025

CVE-2025-47520 on NVD →

Charitable &#8211; Donation Plugin for WordPress &#8211; Fundraising with Recurring Donations &amp; More [charitable] < 1.8.5.2

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Syed Balkhi Charitable allows Stored XSS. This issue affects Charitable: from n/a through 1.8.5.1.

Affected:
up to 1.8.5.2
Fixed in:
1.8.5.2
Disclosed:
May 7, 2025

CVE-2025-47520 on NVD →

Charitable &#8211; Donation Plugin for WordPress &#8211; Fundraising with Recurring Donations &amp; More [charitable] < 1.8.4.8

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Syed Balkhi Charitable allows DOM-Based XSS. This issue affects Charitable: from n/a through 1.8.4.7.

Affected:
up to 1.8.4.8
Fixed in:
1.8.4.8
Disclosed:
Mar 27, 2025

CVE-2025-30770 on NVD →

Charitable <= 1.8.4.7 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Charitable plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.8.4.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages tha...

CVSS:
6.4
Affected:
up to 1.8.4.7
Fixed in:
1.8.4.8
Disclosed:
Mar 26, 2025

CVE-2025-30770 on NVD →

Charitable &#8211; Donation Plugin for WordPress &#8211; Fundraising with Recurring Donations &amp; More [charitable] < 1.8.3.1

unknown

[en] The Charitable – Donation Plugin for WordPress – Fundraising with Recurring Donations & More plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg & remove_query_arg without appropriate escaping on the URL in all versions up to, and including, 1.8.3. This makes it pos...

Affected:
up to 1.8.3.1
Fixed in:
1.8.3.1
Disclosed:
Nov 9, 2024

CVE-2024-10876 on NVD →

Charitable – Donation Plugin for WordPress – Fundraising with Recurring Donations & More <= 1.8.3 - Reflected Cross-Site Scripting

medium

The Charitable – Donation Plugin for WordPress – Fundraising with Recurring Donations & More plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg & remove_query_arg without appropriate escaping on the URL in all versions up to, and including, 1.8.3. This makes it possible...

CVSS:
6.1
Affected:
up to 1.8.3
Fixed in:
1.8.3.1
Disclosed:
Nov 8, 2024

CVE-2024-10876 on NVD →

Charitable &#8211; Donation Plugin for WordPress &#8211; Fundraising with Recurring Donations &amp; More [charitable] < 1.8.1.8

unknown

[en] Missing Authorization vulnerability in Charitable Donations & Fundraising Team Charitable allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Charitable: from n/a through 1.8.1.7.

Affected:
up to 1.8.1.8
Fixed in:
1.8.1.8
Disclosed:
Nov 1, 2024

CVE-2024-37510 on NVD →

Charitable &#8211; Donation Plugin for WordPress &#8211; Fundraising with Recurring Donations &amp; More [charitable] < 1.8.1.8

unknown

[en] Missing Authorization vulnerability in Charitable Donations & Fundraising Team Charitable allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Charitable: from n/a through 1.8.1.7.

Affected:
up to 1.8.1.8
Fixed in:
1.8.1.8
Disclosed:
Nov 1, 2024

CVE-2024-37506 on NVD →

Charitable &#8211; Donation Plugin for WordPress &#8211; Fundraising with Recurring Donations &amp; More [charitable] < 1.8.1.15

unknown

[en] The Donation Forms by Charitable – Donations Plugin & Fundraising Platform for WordPress plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.8.1.14. This is due to the plugin not properly verifying a user's identity when the ID parameter is supplied through the update...

Affected:
up to 1.8.1.15
Fixed in:
1.8.1.15
Disclosed:
Sep 24, 2024

CVE-2024-8791 on NVD →

Donation Forms by Charitable – Donations Plugin & Fundraising Platform for WordPress <= 1.8.1.14 - Insecure Direct Object Reference to Account Takeover and Privilege Escalation

critical

The Donation Forms by Charitable – Donations Plugin & Fundraising Platform for WordPress plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.8.1.14. This is due to the plugin not properly verifying a user's identity when the ID parameter is supplied through the update_core...

CVSS:
9.8
Affected:
up to 1.8.1.14
Fixed in:
1.8.1.15
Disclosed:
Sep 23, 2024

CVE-2024-8791 on NVD →

Charitable <= 1.8.1.7 - Missing Authorization via ajax_license_check()

medium

The Charitable plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ajax_license_check function in versions up to, and including, 1.8.1.7. This makes it possible for unauthenticated attackers to verify a license.

CVSS:
5.3
Affected:
up to 1.8.1.7
Fixed in:
1.8.1.8
Disclosed:
Jul 4, 2024

CVE-2024-37510 on NVD →

Charitable <= 1.8.1.7 - Missing Authorization to Unauthorized Donation

medium

The Charitable plugin for WordPress is vulnerable to unauthorized access due to insufficient verification on the process_donation() function in versions up to, and including, 1.8.1.7. This makes it possible for unauthenticated attackers to donate on forms they shouldn't have access to.

CVSS:
5.3
Affected:
up to 1.8.1.7
Fixed in:
1.8.1.8
Disclosed:
Jul 4, 2024

CVE-2024-37506 on NVD →

Charitable &#8211; Donation Plugin for WordPress &#8211; Fundraising with Recurring Donations &amp; More [charitable] < 1.7.0.14

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Charitable Donations & Fundraising Team Donation Forms by Charitable plugin <= 1.7.0.13 versions.

Affected:
up to 1.7.0.14
Fixed in:
1.7.0.14
Disclosed:
Nov 22, 2023

CVE-2023-47816 on NVD →

Charitable <= 1.7.0.13 - Authenticated(Contributor+) Stored Cross-Site Scripting

medium

The Charitable plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in versions up to, and including, 1.7.0.13 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and...

CVSS:
6.4
Affected:
up to 1.7.0.14
Fixed in:
1.7.0.14
Disclosed:
Oct 11, 2023

CVE-2023-47816 on NVD →

Charitable &#8211; Donation Plugin for WordPress &#8211; Fundraising with Recurring Donations &amp; More [charitable] < 1.7.0.14

unknown

The Charitable plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in versions up to, and including, 1.7.0.13 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and...

Affected:
up to 1.7.0.14
Fixed in:
1.7.0.14
Disclosed:
Oct 11, 2023

Charitable &#8211; Donation Plugin for WordPress &#8211; Fundraising with Recurring Donations &amp; More [charitable] < 1.7.0.13

unknown

[en] The Donation Forms by Charitable plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 1.7.0.12 due to insufficient restriction on the 'update_core_user' function. This makes it possible for unauthenticated attackers to specify their user role by supplying the 'role' paramete...

Affected:
up to 1.7.0.13
Fixed in:
1.7.0.13
Disclosed:
Aug 23, 2023

CVE-2023-4404 on NVD →

Donation Forms by Charitable <= 1.7.0.12 - Unauthenticated Privilege Escalation

critical

The Donation Forms by Charitable plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 1.7.0.12 due to insufficient restriction on the 'update_core_user' function. This makes it possible for unauthenticated attackers to specify their user role by supplying the 'role' parameter dur...

CVSS:
9.8
Affected:
up to 1.7.0.12
Fixed in:
1.7.0.13
Disclosed:
Aug 17, 2023

CVE-2023-4404 on NVD →

Charitable &#8211; Donation Plugin for WordPress &#8211; Fundraising with Recurring Donations &amp; More [charitable] < 1.7.0.11

unknown

[en] Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Charitable Donations & Fundraising Team Donation Forms by Charitable plugin <= 1.7.0.10 versions.

Affected:
up to 1.7.0.11
Fixed in:
1.7.0.11
Disclosed:
May 10, 2023

CVE-2022-47441 on NVD →

Charitable <= 1.7.0.10 - Reflected Cross-Site Scripting

medium

The Charitable plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.7.0.10 due to insufficient input sanitization and output escaping on the 'start_date_from', 'start_date_to', 'end_date_from', and 'end_date_to' parameters. This makes it possible for unauthenticated a...

CVSS:
6.1
Affected:
up to 1.7.0.10
Fixed in:
1.7.0.11
Disclosed:
Apr 19, 2023

CVE-2022-47441 on NVD →

Charitable &#8211; Donation Plugin for WordPress &#8211; Fundraising with Recurring Donations &amp; More [charitable] < 1.6.51

unknown

[en] The Charitable – Donation Plugin WordPress plugin before 1.6.51 is affected by an authenticated stored cross-site scripting vulnerability which was found in the add donation feature.

Affected:
up to 1.6.51
Fixed in:
1.6.51
Disclosed:
Aug 23, 2021

CVE-2021-24531 on NVD →

Charitable – Donation Plugin <= 1.6.50 - Unauthenticated Stored Cross-Site Scripting

high

The Charitable – Donation Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.6.50 due to insufficient input sanitization and output escaping on the 'first_name' parameter. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pa...

CVSS:
7.2
Affected:
up to 1.6.50
Fixed in:
1.6.51
Disclosed:
Jul 21, 2021

Charitable – Donation Plugin <= 1.6.50 - Authenticated Stored Cross-Site Scripting

medium

The Charitable – Donation Plugin WordPress plugin before 1.6.51 is affected by an authenticated stored cross-site scripting vulnerability which was found in the add donation feature.

CVSS:
6.4
Affected:
up to 1.6.50
Fixed in:
1.6.51
Disclosed:
Jul 21, 2021

CVE-2021-24531 on NVD →

Charitable &#8211; Donation Plugin for WordPress &#8211; Fundraising with Recurring Donations &amp; More [charitable] < 1.6.51

unknown

Unauthenticated Stored Cross-Site Scripting (XSS) vulnerability discovered by Eric Daams in WordPress Charitable plugin (versions <= 1.6.50).

Affected:
up to 1.6.51
Fixed in:
1.6.51
Disclosed:
Jul 21, 2021

Charitable &#8211; Donation Plugin for WordPress &#8211; Fundraising with Recurring Donations &amp; More [charitable] < 1.6.51

unknown

The Charitable – Donation Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.6.50 due to insufficient input sanitization and output escaping on the 'first_name' parameter. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pa...

Affected:
up to 1.6.51
Fixed in:
1.6.51
Disclosed:
Jul 21, 2021

Charitable &#8211; Donation Plugin for WordPress &#8211; Fundraising with Recurring Donations &amp; More [charitable] < 1.5.14

unknown

[en] The charitable plugin before 1.5.14 for WordPress has unauthorized access to user and donation details.

Affected:
up to 1.5.14
Fixed in:
1.5.14
Disclosed:
Sep 9, 2019

CVE-2018-21011 on NVD →

Charitable <= 1.5.13 - Unauthorized Access to Information Disclosure

medium

The charitable plugin before 1.5.14 for WordPress has unauthorized access to user and donation details.

CVSS:
5.3
Affected:
up to 1.5.14
Fixed in:
1.5.14
Disclosed:
May 16, 2018

CVE-2018-21011 on NVD →

Charitable &#8211; Donation Plugin for WordPress &#8211; Fundraising with Recurring Donations &amp; More [charitable] < 1.8.6.2

unknown
Affected:
up to 1.8.6.2
Fixed in:
1.8.6.2

CVE-2025-5275 on NVD →

Charitable &#8211; Donation Plugin for WordPress &#8211; Fundraising with Recurring Donations &amp; More [charitable] < 1.6.51

unknown

While fixing an Authenticated Stored Cross-Site Scripting issue (https://wpscan.com/vulnerability/a5837621-ee6e-4876-9f65-82658fc0341f), the vendor identified another Cross-Site Scripting issue, which could be exploited by unauthenticated users and would be triggered in the context of a logged in admin

Affected:
up to 1.6.51
Fixed in:
1.6.51

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database