Stored Cross-Site Scripting Vulnerability in Philantro Plugin for WordPress
CVE-2024-12500
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 18 December 2024
What is CVE-2024-12500?
The Philantro β Donations and Donor Management plugin for WordPress is exposed to a high-severity Stored Cross-Site Scripting (XSS) vulnerability due to inadequate input sanitization and output escaping when processing user-supplied attributes in shortcodes, particularly the 'donate' shortcode. This flaw affects all versions of the plugin up to and including 5.2. Authenticated attackers with contributor-level access can exploit this vulnerability by injecting arbitrary web scripts, leading to malicious code execution on affected pages when accessed by users. This presents significant risks to both site integrity and user data.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Philantro β Donations and Donor Management * <= 5.2
References
CVSS V3.1
Timeline
Vulnerability published