Donorbox – Free Recurring Donation Form <= 7.1.6 - Cross-Site Scripting
medium
The Donorbox WordPress plugin before 7.1.7 does not sanitise and escape its Campaign URL settings before outputting it in an attribute, leading to a Stored Cross-Site Scripting issue even when the unfiltered_html capability is disallowed
- CVSS:
- 5.5
- Affected:
- up to 7.1.6
- Fixed in:
- 7.1.7
- Disclosed:
- Apr 20, 2022
CVE-2022-1396 on NVD →
Donorbox <= 7.1.1 - Authenticated Stored Cross-Site Scripting
medium
The Donorbox plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 7.1.1 via storing shortcodes due to insufficient input sanitization and output escaping. This makes it possible for privileged attackers to inject arbitrary web scripts in pages that will execute whenever a user ac...
- CVSS:
- 6.4
- Affected:
- up to 7.1.2
- Fixed in:
- 7.1.2
- Disclosed:
- Dec 19, 2019
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database