Impact
The Raise The Money plugin contains an improper neutralization of user input that leads to a DOM‑based Cross Site Scripting vulnerability. When an attacker supplies a specially crafted string that is reflected into a web page without adequate sanitization, the malicious script runs in the context of the user’s browser. This can enable session hijacking, cookie theft, defacement of the site, or phishing attacks against visitors.
Affected Systems
WordPress sites that have the Raise The Money plugin version 5.2 or earlier are affected. The issue does not extend to later releases of the plugin, and no other vendors or products appear in the CNA markings.
Risk and Exploitability
The CVSS score of 6.5 denotes a moderate impact for confidentiality, integrity, or availability. With an EPSS score of less than 1%, the likelihood of exploitation in the wild is low, and the vulnerability is not listed in the CISA KEV catalog. Attackers can exploit this by crafting a URL that contains the malicious input and having a user visit the compromised page; no special privileges are required on the server side. The primary risk is to end‑user browsers, potentially compromising user credentials or enabling phishing.
OpenCVE Enrichment
EUVD