CVE-2024-37506
- EPSS 0.1%
- Veröffentlicht 01.11.2024 15:15:29
- Zuletzt bearbeitet 01.11.2024 20:24:53
Missing Authorization vulnerability in Charitable Donations & Fundraising Team Charitable allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Charitable: from n/a through 1.8.1.7.
CVE-2024-37510
- EPSS 0.17%
- Veröffentlicht 01.11.2024 15:15:29
- Zuletzt bearbeitet 01.11.2024 20:24:53
Missing Authorization vulnerability in Charitable Donations & Fundraising Team Charitable allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Charitable: from n/a through 1.8.1.7.
CVE-2024-8791
- EPSS 0.16%
- Veröffentlicht 24.09.2024 03:15:03
- Zuletzt bearbeitet 26.09.2024 16:25:34
The Donation Forms by Charitable – Donations Plugin & Fundraising Platform for WordPress plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.8.1.14. This is due to the plugin not properly verifying a use...
CVE-2023-47816
- EPSS 0.08%
- Veröffentlicht 22.11.2023 23:15:09
- Zuletzt bearbeitet 21.11.2024 08:30:51
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Charitable Donations & Fundraising Team Donation Forms by Charitable plugin <= 1.7.0.13 versions.
CVE-2023-4404
- EPSS 0.24%
- Veröffentlicht 23.08.2023 02:15:08
- Zuletzt bearbeitet 21.11.2024 08:35:04
The Donation Forms by Charitable plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 1.7.0.12 due to insufficient restriction on the 'update_core_user' function. This makes it possible for unauthenticated atta...
CVE-2022-47441
- EPSS 0.08%
- Veröffentlicht 10.05.2023 11:15:10
- Zuletzt bearbeitet 21.11.2024 07:31:57
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Charitable Donations & Fundraising Team Donation Forms by Charitable plugin <= 1.7.0.10 versions.
CVE-2021-24531
- EPSS 0.53%
- Veröffentlicht 23.08.2021 12:15:09
- Zuletzt bearbeitet 21.11.2024 05:53:14
The Charitable – Donation Plugin WordPress plugin before 1.6.51 is affected by an authenticated stored cross-site scripting vulnerability which was found in the add donation feature.
CVE-2018-21011
- EPSS 0.75%
- Veröffentlicht 09.09.2019 13:15:11
- Zuletzt bearbeitet 21.11.2024 04:02:41
The charitable plugin before 1.5.14 for WordPress has unauthorized access to user and donation details.