Stored Cross-Site Scripting Vulnerability in Philantro Plugin for WordPress
CVE-2024-12500

6.4MEDIUM

What is CVE-2024-12500?

The Philantro – Donations and Donor Management plugin for WordPress is exposed to a high-severity Stored Cross-Site Scripting (XSS) vulnerability due to inadequate input sanitization and output escaping when processing user-supplied attributes in shortcodes, particularly the 'donate' shortcode. This flaw affects all versions of the plugin up to and including 5.2. Authenticated attackers with contributor-level access can exploit this vulnerability by injecting arbitrary web scripts, leading to malicious code execution on affected pages when accessed by users. This presents significant risks to both site integrity and user data.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

Philantro – Donations and Donor Management * <= 5.2

References

CVSS V3.1

Score:
6.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

.