Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by vendor Donation Button Project Subscribe
Filtered by product Donation Button
Total 2 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-4004 1 Donation Button Project 1 Donation Button 2022-12-15 N/A 4.3 MEDIUM
The Donation Button WordPress plugin through 4.0.0 does not properly check for privileges and nonce tokens in its "donation_button_twilio_send_test_sms" AJAX action, which may allow any users with an account on the affected site, like subscribers, to use the plugin's Twilio integration to send SMSes to arbitrary phone numbers.
CVE-2022-4005 1 Donation Button Project 1 Donation Button 2022-12-15 N/A 5.4 MEDIUM
The Donation Button WordPress plugin through 4.0.0 does not sanitize and escapes some parameters, which could allow users with a role as low as Contributor to perform Cross-Site Scripting attacks.