CVE-2025-15675

The Charitable WordPress plugin before 1.8.5.3 does not sanitise and escape one of its campaign image text fields before outputting it in an HTML attribute, allowing users with a high-privilege campaign-management role to perform Stored Cross-Site Scripting attacks that execute on the front-end campaign page.
Configurations

No configuration.

History

No history.

Information

Published : 2026-08-02 06:16

Updated : 2026-08-26 16:31


NVD link : CVE-2025-15675

Mitre link : CVE-2025-15675

CVE.ORG link : CVE-2025-15675


JSON object : View

Products Affected

No product.

CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')