plugin

Donorbox Donation Form Vulnerabilities

2 known security issues reported for the Donorbox Donation Form WordPress plugin. Most recent disclosed Apr 20, 2022.

2 medium

Running Donorbox Donation Form on your site? Check whether your installed version is affected.

Scan your site free

Donorbox – Free Recurring Donation Form <= 7.1.6 - Cross-Site Scripting

medium

The Donorbox WordPress plugin before 7.1.7 does not sanitise and escape its Campaign URL settings before outputting it in an attribute, leading to a Stored Cross-Site Scripting issue even when the unfiltered_html capability is disallowed

CVSS:
5.5
Affected:
up to 7.1.6
Fixed in:
7.1.7
Disclosed:
Apr 20, 2022

CVE-2022-1396 on NVD →

Donorbox <= 7.1.1 - Authenticated Stored Cross-Site Scripting

medium

The Donorbox plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 7.1.1 via storing shortcodes due to insufficient input sanitization and output escaping. This makes it possible for privileged attackers to inject arbitrary web scripts in pages that will execute whenever a user ac...

CVSS:
6.4
Affected:
up to 7.1.2
Fixed in:
7.1.2
Disclosed:
Dec 19, 2019

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database