Charitable

WordPress plugin · charitable · WordPress.org ↗
0
Critical
0
High
2
Known total
0
Unfixed
Running Charitable on your site? WP Alerts checks your installed version against every entry below and emails you only when one affects you. Free, no tracking.
Scan a site Monitor my sites →
SeverityVulnerabilityAffectedFixed inCVEPublished
MEDIUM
CVSS 5.3
Charitable < 1.8.12 - Unauthenticated Donation Payment-Status Manipulation via Square Webhook Signature Bypass
CVE.org
>=0, <1.8.12 v1.8.12 CVE-2026-16650 Aug 21, 2026
MEDIUM
CVSS 4.8
Charitable < 1.8.5.3 - Admin+ Stored XSS via Photo Field ALT Text
CVE.org
>=0, <1.8.5.3 v1.8.5.3 CVE-2025-15675 Aug 2, 2026

Data aggregated from WPVulnerability, NVD/NIST, ENISA EUVD, CVE.org and WordPress.org. Provided as-is; verify with the plugin author before acting. Disclaimer.