Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in crea8xion Charity-thermometer charitydonation-thermometer allows Stored XSS.This issue affects Charity-thermometer: from n/a through <= 1.1.2.
Published: 2025-01-16
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Improper neutralization of user input in the Charity‑thermometer plugin results in stored Cross‑Site Scripting (XSS). When an attacker supplies malicious scripts through any input field that the plugin saves and later displays, any visitor to the affected page can execute the injected code in the context of that website. The impact is primarily client‑side exploitation, allowing cookie theft, session hijacking, defacement, or the delivery of additional malware. This weakness corresponds to CWE‑79.

Affected Systems

The vulnerability affects all installations of the crea8xion Charity‑thermometer plugin with version numbers up to and including 1.1.2. No specific sub‑versions are listed, so any build of the plugin released prior to 1.1.3 is considered affected.

Risk and Exploitability

The CVSS score of 6.5 indicates a medium severity, and the very low EPSS score (< 1 %) suggests that the exploitation probability is currently low. The vulnerability is not present in the CISA KEV catalog. Based on the description, the likely attack vector is a user interacting with the plugin’s input interface—such as submitting a donation or pledging information—that is then persisted and rendered on pages viewed by other users. An adversary can inject script payloads that will be executed in the browsers of any user who loads the compromised page. Because the issue is a stored XSS, an authentic user with the ability to contribute content is sufficient to trigger the vulnerability; no administrative privileges are required.

Generated by OpenCVE AI on May 2, 2026 at 09:40 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Charity‑thermometer plugin to a release newer than 1.1.2, if one is available, to remove the stored XSS flaw.
  • If an upgrade is not possible, disable or uninstall the Charity‑thermometer plugin to eliminate the attack surface.
  • Configure a web application firewall or content‑security‑policy to block or sanitize script tags in data stored by the plugin.

Generated by OpenCVE AI on May 2, 2026 at 09:40 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-3481 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Eyouth { rob.panes } Charity-thermometer allows Stored XSS.This issue affects Charity-thermometer: from n/a through 1.1.2.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Eyouth { rob.panes } Charity-thermometer allows Stored XSS.This issue affects Charity-thermometer: from n/a through 1.1.2. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in crea8xion Charity-thermometer charitydonation-thermometer allows Stored XSS.This issue affects Charity-thermometer: from n/a through <= 1.1.2.
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Fri, 17 Jan 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 16 Jan 2025 20:30:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Eyouth { rob.panes } Charity-thermometer allows Stored XSS.This issue affects Charity-thermometer: from n/a through 1.1.2.
Title WordPress Charity-thermometer plugin <= 1.1.2 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-05-11T22:48:31.709Z

Reserved: 2025-01-16T11:31:13.711Z

Link: CVE-2025-23860

cve-icon Vulnrichment

Updated: 2025-01-17T17:17:41.938Z

cve-icon NVD

Status : Deferred

Published: 2025-01-16T21:15:25.810

Modified: 2026-06-17T08:57:37.990

Link: CVE-2025-23860

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-02T09:45:36Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')