Extension WordPress
Vulnérabilités Charitable – Donation & Fundraising Platform (Donation Forms, Recurring Donations & Fundraising Campaigns)
Cette page rassemble les failles publiées pour Charitable – Donation & Fundraising Platform (Donation Forms, Recurring Donations & Fundraising Campaigns), leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Charitable – Donation & Fundraising Platform (Donation Forms, Recurring Donations & Fundraising Campaigns)
17 fiches
Charitable <= 1.8.11.1 – Authenticated (Subscriber+) Insecure Direct Object Reference to Arbitrary Attachment Deletion via 'avatar' Parameter
The Charitable – Donation Plugin for WordPress – Fundraising with Recurring Donations & More plugin for WordPress is vulnerable to Insecure Direct Object Reference / Authorization Bypass leading to Arbitrary Attachment Deletion in versions up to, and including,…
*-1.8.11.1
1.8.11.2
05/06/2026
Charitable <= 1.8.10.4 – Authenticated (Custom+) SQL Injection via 's' Search Parameter
The Charitable – Donation Plugin for WordPress – Fundraising with Recurring Donations & More plugin for WordPress is vulnerable to generic SQL Injection via the 's' parameter in all versions up to, and including, 1.8.10.4 due to insufficient…
*-1.8.10.4
1.8.10.5
12/05/2026
Charitable – Donation Plugin for WordPress – Fundraising with Recurring Donations & More <= 1.8.9.7 – Insufficient Verification of Data Authenticity to Unauthenticated Donation Status Forgery via Stripe Webhook
The Charitable – Donation Plugin for WordPress – Fundraising with Recurring Donations & More plugin for WordPress is vulnerable to Insufficient Verification of Data Authenticity in versions up to, and including, 1.8.9.7. This is due to missing cryptographic…
*-1.8.9.7
1.8.10
06/04/2026
Charitable – Donation Plugin for WordPress – Fundraising with Recurring Donations & More <= 1.8.8.4 – Authenticated (Subscriber+) SQL Injection
The Charitable – Donation Plugin for WordPress – Fundraising with Recurring Donations & More plugin for WordPress is vulnerable to SQL Injection via the donation_ids parameter in all versions up to, and including, 1.8.8.4 due to insufficient escaping…
*-1.8.8.4
1.8.8.5
24/10/2025
Charitable <= 1.8.6.1 – Authenticated (Administrator+) Stored Cross-Site Scripting via Plugin's Privacy Settings
The Charitable – Donation Plugin for WordPress – Fundraising with Recurring Donations & More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the privacy settings fields in all versions up to, and including, 1.8.6.1 due to…
*-1.8.6.1
1.8.6.2
25/06/2025
Charitable <= 1.8.5.1 – Authenticated (Administrator+) Stored Cross-Site Scripting
The Charitable plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.8.5.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access and above,…
*-1.8.5.1
1.8.5.2
07/05/2025
Charitable <= 1.8.4.7 – Authenticated (Contributor+) Stored Cross-Site Scripting
The Charitable plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.8.4.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above,…
*-1.8.4.7
1.8.4.8
26/03/2025
Charitable – Donation Plugin for WordPress – Fundraising with Recurring Donations & More <= 1.8.3 – Reflected Cross-Site Scripting
The Charitable – Donation Plugin for WordPress – Fundraising with Recurring Donations & More plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg & remove_query_arg without appropriate escaping on the URL in…
*-1.8.3
1.8.3.1
08/11/2024
Donation Forms by Charitable – Donations Plugin & Fundraising Platform for WordPress <= 1.8.1.14 – Insecure Direct Object Reference to Account Takeover and Privilege Escalation
The Donation Forms by Charitable – Donations Plugin & Fundraising Platform for WordPress plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.8.1.14. This is due to the plugin not properly verifying…
*-1.8.1.14
1.8.1.15
23/09/2024
Charitable <= 1.8.1.7 – Missing Authorization to Unauthorized Donation
The Charitable plugin for WordPress is vulnerable to unauthorized access due to insufficient verification on the process_donation() function in versions up to, and including, 1.8.1.7. This makes it possible for unauthenticated attackers to donate on forms they shouldn't…
*-1.8.1.7
1.8.1.8
04/07/2024
Charitable <= 1.8.1.7 – Missing Authorization via ajax_license_check()
The Charitable plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ajax_license_check function in versions up to, and including, 1.8.1.7. This makes it possible for unauthenticated attackers to verify…
*-1.8.1.7
1.8.1.8
04/07/2024
Charitable <= 1.7.0.13 – Authenticated(Contributor+) Stored Cross-Site Scripting
The Charitable plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in versions up to, and including, 1.7.0.13 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible…
[*, 1.7.0.14)
1.7.0.14
11/10/2023
Donation Forms by Charitable <= 1.7.0.12 – Unauthenticated Privilege Escalation
The Donation Forms by Charitable plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 1.7.0.12 due to insufficient restriction on the 'update_core_user' function. This makes it possible for unauthenticated attackers to specify their…
*-1.7.0.12
1.7.0.13
17/08/2023
Charitable <= 1.7.0.10 – Reflected Cross-Site Scripting
The Charitable plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.7.0.10 due to insufficient input sanitization and output escaping on the 'start_date_from', 'start_date_to', 'end_date_from', and 'end_date_to' parameters. This makes it possible…
*-1.7.0.10
1.7.0.11
19/04/2023
Charitable – Donation Plugin <= 1.6.50 – Unauthenticated Stored Cross-Site Scripting
The Charitable – Donation Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.6.50 due to insufficient input sanitization and output escaping on the 'first_name' parameter. This makes it possible for…
*-1.6.50
1.6.51
21/07/2021
Charitable – Donation Plugin <= 1.6.50 – Authenticated Stored Cross-Site Scripting
The Charitable – Donation Plugin WordPress plugin before 1.6.51 is affected by an authenticated stored cross-site scripting vulnerability which was found in the add donation feature.
*-1.6.50
1.6.51
21/07/2021
Charitable <= 1.5.13 – Unauthorized Access to Information Disclosure
The charitable plugin before 1.5.14 for WordPress has unauthorized access to user and donation details.
[*, 1.5.14)
1.5.14
16/05/2018
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.