Impact
The WP Attractive Donations System plugin contains a blind SQL Injection flaw caused by improper neutralization of special characters in SQL statements. An attacker who supplies crafted input can read sensitive database contents, such as user details or donation records, without needing prior authentication.
Affected Systems
Any WordPress site that has the loopus WP Attractive Donations System – Easy Stripe & Paypal donations plugin installed with a version up to and including 1.25 is affected. This includes all releases where the maximum supported version is 1.25.
Risk and Exploitability
The CVSS score of 9.3 places this vulnerability in the critical range, while the EPSS score of less than 1 % suggests a very low current exploitation probability. The flaw is not listed in the CISA KEV catalog. Exploitation can be achieved remotely by sending specially crafted requests to the plugin’s donation endpoints, allowing an attacker to extract confidential information from the database.
OpenCVE Enrichment