Impact
An improper neutralization of user input in the algothemes Causes – Donation Plugin allows an attacker to inject malicious scripts that will execute in the context of a victim’s browser. The vulnerability can be triggered by including crafted query parameters in a URL to the donation plugin, causing the application to echo the value directly into a page without proper sanitization. The result is a classic reflected XSS that can lead to session hijacking, credential theft, or other malicious actions executed in the victim’s session.
Affected Systems
The plugin version 1.0.01 or earlier is impacted. Any WordPress site that has installed the algothemes Causes – Donation Plugin at a version older than 1.0.01 is vulnerable.
Risk and Exploitability
The CVSS v3.1 score of 7.1 indicates a high impact of the vulnerability. The EPSS score of less than 1% suggests that exploitation is currently rare, and the vulnerability is not listed in the CISA KEV catalog. Attackers would typically need to persuade a user to click a specially crafted link or exploit a social engineering scenario. Once triggered, the XSS can compromise the victim’s browser session and potentially the site’s data.
OpenCVE Enrichment
EUVD