Browse all 4 CVE security advisories affecting Charitable Donations & Fundraising Team. AI-powered Chinese analysis, POCs, and references for each vulnerability.
The Charitable Donations & Fundraising Team manages online donation platforms and donor management systems, processing financial transactions and sensitive personal information. Historically, common vulnerabilities include stored XSS in donation forms, RCE in payment processing components, and privilege escalation flaws in admin panels. Notable characteristics include handling PCI-DSS regulated payment data and processing high-volume transactions during fundraising campaigns. The team has addressed 4 CVEs, primarily involving input validation failures in donation web applications and insecure direct object references in donor profile management. Security incidents have included unauthorized access to donor databases due to misconfigured authentication controls.
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2024-37506 | WordPress Donation Forms by Charitable plugin <= 1.8.1.7 - Broken Access Control vulnerability — CharitableCWE-862 | 5.3 | Medium | 2024-11-01 |
| CVE-2024-37510 | WordPress Donation Forms by Charitable plugin <= 1.8.1.7 - Broken Access Control vulnerability — CharitableCWE-862 | 6.5 | Medium | 2024-11-01 |
| CVE-2023-47816 | WordPress Charitable Plugin <= 1.7.0.13 is vulnerable to Cross Site Scripting (XSS) — Donation Forms by CharitableCWE-79 | 6.5 | Medium | 2023-11-22 |
| CVE-2022-47441 | WordPress Charitable Plugin <= 1.7.0.10 is vulnerable to Cross Site Scripting (XSS) — Donation Forms by CharitableCWE-79 | 7.1 | High | 2023-05-10 |
This page lists every published CVE security advisory associated with Charitable Donations & Fundraising Team. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.