3 results (0.030 seconds)

CVSS: 8.8EPSS: 0%CPEs: 1EXPL: 0

Cross-Site Request Forgery (CSRF) vulnerability in RedNao Donations Made Easy – Smart Donations.This issue affects Donations Made Easy – Smart Donations: from n/a through 4.0.12. Vulnerabilidad de Cross-Site Request Forgery (CSRF) en RedNao Donations Made Easy – Smart Donations. Este problema afecta a Donations Made Easy – Smart Donations: desde n/a hasta 4.0.12. The Donations Made Easy – Smart Donations plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.0.12. This is due to missing or incorrect nonce validation on an unknown function. • https://patchstack.com/database/vulnerability/smart-donations/wordpress-donations-made-easy-smart-donations-plugin-4-0-12-cross-site-request-forgery-csrf-vulnerability?_s_id=cve • CWE-352: Cross-Site Request Forgery (CSRF) •

CVSS: 7.1EPSS: 0%CPEs: 1EXPL: 0

Cross-Site Request Forgery (CSRF) vulnerability in RedNao Donations Made Easy – Smart Donations allows Stored XSS.This issue affects Donations Made Easy – Smart Donations: from n/a through 4.0.12. Vulnerabilidad de Cross-Site Request Forgery (CSRF) en RedNao Donations Made Easy – Smart Donations permite almacenar XSS. Este problema afecta a Donations Made Easy – Smart Donations: desde n/a hasta 4.0.12. The Donations Made Easy – Smart Donations plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.0.12 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. • https://patchstack.com/database/vulnerability/smart-donations/wordpress-donations-made-easy-smart-donations-plugin-4-0-12-cross-site-scripting-xss-vulnerability-2?_s_id=cve • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CWE-352: Cross-Site Request Forgery (CSRF) •

CVSS: 9.8EPSS: 0%CPEs: 1EXPL: 0

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in RedNao Donations Made Easy – Smart Donations allows SQL Injection.This issue affects Donations Made Easy – Smart Donations: from n/a through 4.0.12. La neutralización incorrecta de elementos especiales utilizados en una vulnerabilidad de comando SQL ('Inyección SQL') en RedNao Donations Made Easy – Smart Donations permite la inyección de SQL. Este problema afecta a Donations Made Easy – Smart Donations: desde n/a hasta 4.0.12. The Donations Made Easy – Smart Donations plugin for WordPress is vulnerable to SQL Injection via an unknown parameter in versions up to, and including, 4.0.12 due to insufficient escaping on a user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with administrator-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. • https://patchstack.com/database/vulnerability/smart-donations/wordpress-donations-made-easy-smart-donations-plugin-4-0-12-sql-injection?_s_id=cve • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •