Donations <= 1.8 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Donations plugin <= 1.8 for WordPress is vulnerable to Authenticated stored Cross-Site Scripting (XSS) by users with the contributor role or higher
- CVSS:
- 6.4
- Affected:
- up to 1.8
- Fix:
- No patched version reported
- Disclosed:
- May 13, 2022
CVE-2022-29433 on NVD →
Donations [nd-donations] <= 1.8 (closed)
unknown
[en] Authenticated (contributor or higher role) Cross-Site Scripting (XSS) vulnerability in Donations plugin <= 1.8 on WordPress.
- Affected:
- up to 1.8
- Fixed in:
- 1.8
- Disclosed:
- May 13, 2022
CVE-2022-29433 on NVD →
Donations [nd-donations] <= 1.8 (unfixed + closed)
unknown
[en] The Donations WordPress plugin through 1.8 does not sanitise and escape the nd_donations_id parameter before using it in a SQL statement via the nd_donations_single_cause_form_validate_fields_php_function AJAX action (available to unauthenticated users), leading to an unauthenticated SQL Injection
- Affected:
- up to 1.8
- Fix:
- No patched version reported
- Disclosed:
- Apr 25, 2022
CVE-2022-0782 on NVD →
Donations <= 1.8 - Unauthenticated SQL Injection
critical
The Donations WordPress plugin through 1.8 does not sanitise and escape the nd_donations_id parameter before using it in a SQL statement via the nd_donations_single_cause_form_validate_fields_php_function AJAX action (available to unauthenticated users), leading to an unauthenticated SQL Injection
- CVSS:
- 9.8
- Affected:
- up to 1.8
- Fix:
- No patched version reported
- Disclosed:
- Mar 29, 2022
CVE-2022-0782 on NVD →
Donations [nd-donations] < 1.4 (closed)
unknown
[en] The nd-donations plugin before 1.4 for WordPress has a nopriv_ AJAX action that allows modification of the siteurl setting.
- Affected:
- up to 1.4
- Fixed in:
- 1.4
- Disclosed:
- Aug 29, 2019
CVE-2019-15772 on NVD →
Donations [nd-donations] < 1.3.1 (closed)
unknown
Unauthenticated Options Change vulnerability found by Jerome Bruandet (Nintechnet) in WordPress Donations plugin (versions <= 1.3).
- Affected:
- up to 1.3.1
- Fixed in:
- 1.3.1
- Disclosed:
- Aug 6, 2019
Donations < 1.4 - Unauthenticated Arbitrary Options Change
high
The Donations plugin before 1.4 for WordPress has a nopriv_ AJAX action that allows modification of the siteurl setting.
- CVSS:
- 8.2
- Affected:
- up to 1.4
- Fixed in:
- 1.4
- Disclosed:
- Aug 3, 2019
CVE-2019-15772 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database