CVE-2024-13690

CVSS 3.1 Score 7.2 of 10 (high)

Details

Published Mar 25, 2025
Updated: Mar 27, 2025
CWE ID 79

Summary

CVE-2024-13690 is a Stored Cross-Site Scripting (XSS) vulnerability affecting the WP Church Donation plugin for WordPress. Versions up to and including 1.7 are vulnerable. This issue stems from insufficient input sanitization and output escaping in donation form submission parameters. An attacker can exploit this vulnerability to inject arbitrary web scripts, which execute when a user accesses an injected page, potentially compromising the user's data or taking control of their account. Unauthenticated attackers can leverage this to target unsuspecting visitors to the vulnerable website.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share