CVE-2025-15675
Received Received - Intake

Stored XSS in Charitable WordPress Plugin

Vulnerability report for CVE-2025-15675, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-02

Last updated on: 2026-08-02

Assigner: WPScan

Description

The Charitable WordPress plugin before 1.8.5.3 does not sanitise and escape one of its campaign image text fields before outputting it in an HTML attribute, allowing users with a high-privilege campaign-management role to perform Stored Cross-Site Scripting attacks that execute on the front-end campaign page.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-02
Last Modified
2026-08-02
Generated
2026-08-02
AI Q&A
2026-08-02
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
charitable charitable to 1.8.5.3 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a Stored Cross-Site Scripting (XSS) issue in the Charitable WordPress plugin before version 1.8.5.3. It occurs because the plugin fails to properly sanitize and escape a campaign image text field before displaying it in an HTML attribute. This allows users with high-privilege campaign-management roles to inject malicious scripts that execute when the front-end campaign page is viewed.

Detection Guidance

Check if the Charitable WordPress plugin version is below 1.8.5.3. Inspect campaign image text fields for unsanitized input. Use WordPress admin panel to review plugin versions and settings.

Impact Analysis

If exploited, this vulnerability could allow attackers to execute arbitrary scripts in the context of a user's browser when they view the affected campaign page. This could lead to theft of session cookies, account takeover, or defacement of the website. Users with high-privilege roles are the primary risk as they can introduce the malicious payload.

Compliance Impact

This vulnerability could potentially impact compliance with GDPR and HIPAA by enabling stored cross-site scripting (XSS) attacks. Such attacks may lead to unauthorized data access, manipulation, or exfiltration, which are violations of GDPR's data protection requirements and HIPAA's safeguards for protected health information.

Mitigation Strategies

Update the Charitable plugin to version 1.8.5.3 or higher immediately. Review and sanitize all campaign image text fields. Restrict high-privilege roles to trusted users only.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2025-15675. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart