Impact
The WP‑SOS‑Donate Donation Sidebar Plugin does not sanitize the value of $_SERVER['PHP_SELF'] before outputting it. This omission allows an unauthenticated attacker to inject arbitrary JavaScript into pages that are then executed if a user follows a crafted link or performs a similar action. The vulnerability exists in all versions up to and including 0.9.2.
Affected Systems
All installations of switch2mac’s WP‑SOS‑Donate Donation Sidebar Plugin through version 0.9.2 are affected. Any WordPress site that has deployed these plugin versions is vulnerable, as the admin options page outputs the unsanitized server variable.
Risk and Exploitability
The CVSS score of 6.1 indicates moderate severity, while the EPSS score of less than 1 % reflects a low likelihood of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. Because the flaw requires a victim to interact with a link containing the malicious payload, it can be delivered via phishing or similar social engineering. The impact is limited to the victim’s browser, but the overall risk remains moderate due to the need for user interaction.
OpenCVE Enrichment