Stored XSS Vulnerability in Donate Visa Plugin by Saul Morales Pacheco
CVE-2025-23656
6.5MEDIUM
Key Information:
- Vendor
- Saul Morales Pacheco
- Status
- Donate Visa
- Vendor
- CVE Published:
- 27 January 2025
Summary
A Missing Authorization vulnerability in the Donate Visa plugin developed by Saul Morales Pacheco allows for Stored Cross-Site Scripting (XSS) attacks. Attackers can exploit this issue on versions from n/a up to 1.0.0, potentially leading to the execution of malicious scripts in the context of an authenticated user, which can compromise user data and site security.
Affected Version(s)
Donate visa <= 1.0.0
References
CVSS V3.1
Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
SOPROBRO (Patchstack Alliance)