Impact
The WP Donate plugin for WordPress accepts user input that is not properly neutralised when generating web pages, allowing stored cross‑site scripting. An attacker can inject malicious scripts into content managed by the plugin, which will execute in the browsers of any visitor who loads the affected pages.
Affected Systems
WordPress installations that include the WP Donate plugin by ketanajani, versions from n/a through <= 2.0. The vulnerability applies to any site hosting this plugin, regardless of the WordPress core version.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity, while the EPSS score of less than 1% suggests a low overall exploitation probability at the moment. The vulnerability is not listed in the CISA KEV catalog. Attackers may submit malicious input through the plugin’s input mechanisms, which is inferred from the description. Once the content is stored, it will execute in the browsers of users visiting the affected pages, making this a significant risk for any site where attackers can submit arbitrary content.
OpenCVE Enrichment
EUVD