← Back

Donations Project

donations_project

3 CVEs • 1 product

Products (1)

Click to collapse
Toggle
Donations
donations

CVEs (3)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Donations Project
1Donations
Jun 17, 2026
May 13, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Authenticated (contributor or higher role) Cross-Site Scripting (XSS) vulnerability in Donations plugin <= 1.8 on WordPress.
1Donations Project
1Donations
Jun 17, 2026
Apr 25, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The Donations WordPress plugin through 1.8 does not sanitise and escape the nd_donations_id parameter before using it in a SQL statement via the nd_donations_single_cause_form_validate_fields_php_function AJAX action (av...Show more
The Donations WordPress plugin through 1.8 does not sanitise and escape the nd_donations_id parameter before using it in a SQL statement via the nd_donations_single_cause_form_validate_fields_php_function AJAX action (available to unauthenticated users), leading to an unauthenticated SQL InjectionShow less
1Donations Project
1Donations
Jun 17, 2026
Aug 29, 2019
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
The nd-donations plugin before 1.4 for WordPress has a nopriv_ AJAX action that allows modification of the siteurl setting.