First published: Wed Sep 27 2023(Updated: )
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in RedNao Donations Made Easy – Smart Donations plugin <= 4.0.12 versions.
Credit: audit@patchstack.com audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Rednao Smart Donations | <=4.0.12 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-40664 refers to an Unauthenticated Reflected Cross-Site Scripting (XSS) vulnerability in the RedNao Donations Made Easy - Smart Donations plugin version <= 4.0.12 for WordPress.
CVE-2023-40664 has a severity rating of 6.1 (High).
CVE-2023-40664 allows an attacker to inject and execute malicious scripts in the context of an unsuspecting user's browser when they visit a specially crafted web page.
Yes, updating the RedNao Donations Made Easy - Smart Donations plugin to a version beyond 4.0.12 will fix the vulnerability.
CVE-2023-40664 is classified as CWE-79, which refers to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting').