All 7 CVE vulnerabilities found in Charitable, with AI-generated Chinese analysis, references, and POCs.
Vendor: Charitable Donations & Fundraising Team
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-16650 | Charitable < 1.8.12 - Unauthenticated Donation Payment-Status Manipulation via Square Webhook Signature Bypass | 5.3 | Medium | 2026-08-21 |
| CVE-2026-73994 | WordPress Charitable plugin <= 1.8.11.3 - Broken Access Control vulnerability CWE-862 | 7.5 | High | 2026-08-18 |
| CVE-2025-15675 | Charitable < 1.8.5.3 - Admin+ Stored XSS via Photo Field ALT Text | - | - | 2026-08-02 |
| CVE-2025-47520 | WordPress Charitable plugin <= 1.8.5.1 - Cross Site Scripting (XSS) Vulnerability CWE-79 | 5.9 | Medium | 2025-05-07 |
| CVE-2025-30770 | WordPress Charitable plugin <= 1.8.4.7 - Cross Site Scripting (XSS) Vulnerability CWE-79 | 6.5 | Medium | 2025-03-27 |
| CVE-2024-37506 | WordPress Donation Forms by Charitable plugin <= 1.8.1.7 - Broken Access Control vulnerability CWE-862 | 5.3 | Medium | 2024-11-01 |
| CVE-2024-37510 | WordPress Donation Forms by Charitable plugin <= 1.8.1.7 - Broken Access Control vulnerability CWE-862 | 6.5 | Medium | 2024-11-01 |
All 7 known CVE vulnerabilities affecting Charitable with full Chinese analysis, references, and POCs where available.