The Charitable WordPress plugin before 1.8.5.3 does not sanitise and escape one of its campaign image text fields before outputting it in an HTML attribute, allowing users with a high-privilege campaign-management role to perform Stored Cross-Site Scripting attacks that execute on the front-end campaign page.

Project Subscriptions

Vendors Products
Wordpress Subscribe
Wordpress Subscribe
Wpcharitable Subscribe
Charitable Subscribe
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Sun, 02 Aug 2026 19:15:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress
Wordpress wordpress
Wpcharitable
Wpcharitable charitable
Vendors & Products Wordpress
Wordpress wordpress
Wpcharitable
Wpcharitable charitable

Sun, 02 Aug 2026 06:15:00 +0000

Type Values Removed Values Added
Description The Charitable WordPress plugin before 1.8.5.3 does not sanitise and escape one of its campaign image text fields before outputting it in an HTML attribute, allowing users with a high-privilege campaign-management role to perform Stored Cross-Site Scripting attacks that execute on the front-end campaign page.
Title Charitable < 1.8.5.3 - Admin+ Stored XSS via Photo Field ALT Text
References

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-08-02T06:00:13.349Z

Reserved: 2026-07-22T14:38:54.933Z

Link: CVE-2025-15675

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T19:00:04Z

Weaknesses

No weakness.