Impact
The vulnerability is an improper neutralization of input during web page generation that allows reflected XSS. An attacker can supply malicious scripts that will be executed in the browser of any user who views the affected page, potentially enabling session hijacking, defacement, or the delivery of further malware. This weakness is identified as CWE‑79 and requires that user input be properly escaped before rendering.
Affected Systems
The affected product is the Donate Me plugin by raphaelheide, version 1.2.5 and earlier. All releases from the initial version through 1.2.5 are vulnerable.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate severity risk. The EPSS score of less than 1% suggests that, as of the latest data, the probability of exploitation is very low. This vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog, meaning there is no confirmed exploitation in the wild. Exploitation would involve delivering a crafted URL or input that causes the plugin to render an attacker‑supplied script, which would then run in the victim’s browser when the page is loaded.
OpenCVE Enrichment
EUVD