Impact
The Simple Donate plugin for WordPress contains a stored XSS flaw in its shortcode. Authenticated users who can add or edit content with contributor privileges can supply attribute values that are not sanitized or escaped. When a malicious value containing script tags is embedded, it is stored and rendered as part of a page. Consequently, any visitor who loads that page will execute the injected payload in their browser context.
Affected Systems
Affected systems are sites that run the Simple Donate plugin version 1.0 or earlier on the WordPress platform. The vendor identified by the CNA is ethoseo, and the product name is Simple Donate. No specific minor or patch versions are listed, so any installation of the plugin in a version ≤1.0 is considered vulnerable.
Risk and Exploitability
The CVSS score of 6.4 indicates medium severity. The EPSS value of <1% suggests that exploitation is unlikely in the wild, and the vulnerability is not currently listed in CISA’s KEV. However, the attack vector relies on a legitimate contributor account, which is common in many WordPress deployments. Once exploited, the attacker can run arbitrary scripts on the affected site, enabling phishing, credential theft, defacement, or the execution of additional client‑side attacks against all users who view the injected page.
OpenCVE Enrichment