Stored XSS Vulnerability in Donate Visa Plugin by Saul Morales Pacheco
CVE-2025-23656
6.5MEDIUM
What is CVE-2025-23656?
A Missing Authorization vulnerability in the Donate Visa plugin developed by Saul Morales Pacheco allows for Stored Cross-Site Scripting (XSS) attacks. Attackers can exploit this issue on versions from n/a up to 1.0.0, potentially leading to the execution of malicious scripts in the context of an authenticated user, which can compromise user data and site security.
Affected Version(s)
Donate visa <= 1.0.0