Cross-Site Scripting Vulnerability in Charitable by Syed Balkhi
CVE-2025-30770
6.5MEDIUM
What is CVE-2025-30770?
A vulnerability exists in the Charitable plugin developed by Syed Balkhi, which allows for improper neutralization of input during web page generation, leading to a DOM-Based Cross-Site Scripting (XSS) attack. This issue affects versions ranging from n/a through 1.8.4.7, potentially enabling malicious actors to inject arbitrary scripts into web pages viewed by users of the affected plugin, compromising user data and security.
Affected Version(s)
Charitable 0 <= 1.8.4.7
