WordPress Donations Made Easy – Smart Donations Plugin <= 4.0.12 is vulnerable to Cross Site Scripting (XSS)
CVE-2023-40664
7.1HIGH
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 27 September 2023
What is CVE-2023-40664?
The RedNao Donations Made Easy – Smart Donations plugin is prone to a reflected Cross-Site Scripting (XSS) vulnerability, allowing attackers to inject malicious scripts into web pages displayed to users. This flaw affects versions up to 4.0.12, potentially exposing users to harmful actions such as data theft or session hijacking when they interact with the compromised application.
Affected Version(s)
Donations Made Easy – Smart Donations <= 4.0.12