First published: Sun Dec 01 2024(Updated: )
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Berg Informatik Stripe Donation allows Stored XSS.This issue affects Stripe Donation: from n/a through 1.2.5.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Stripe Donation | >=n/a<1.2.5 | |
Stripe Donation plugin for WordPress | <=1.2.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2024-53752 is classified as high due to the potential for stored cross-site scripting attacks.
To fix CVE-2024-53752, upgrade the Berg Informatik Stripe Donation plugin to a version later than 1.2.5.
CVE-2024-53752 allows attackers to execute stored XSS attacks, potentially compromising user data and sessions.
Users of Berg Informatik Stripe Donation and WordPress Stripe Donation versions up to and including 1.2.5 are affected by CVE-2024-53752.
CVE-2024-53752 is not a zero-day vulnerability as it has been publicly disclosed and mitigation measures are available.