CVE-2025-23656 MEDIUM

CVE-2025-23656: WordPress Donate visa plugin <= 1.0.0 - Stored Cross Site Scripting (XSS) vulnerability

Vendor Saul Morales Pacheco
Product Donate visa
Weakness CWE-862 · Missing authorization
Published January 27, 2025
Last update April 28, 2026

CVSS base score

6.5/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction Required
Confidentiality Low
Integrity Low

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L

What the vulnerability does

01Description

Missing Authorization vulnerability in Saul Morales Pacheco Donate visa donate-visa allows Stored XSS.This issue affects Donate visa: from n/a through <= 1.0.0.

Explanation of Vulnerability in Simple Terms

02Summary

Donate visa version 1.0.0 and earlier lacks proper authorization checks, allowing authenticated users to perform actions they should not be permitted to perform. The vulnerability requires user interaction and can affect confidentiality, integrity, and availability of the application. A low-privileged user can exploit this to access or modify data beyond their intended scope.

What an attacker can do

03Attacker Capabilities

An authenticated user can perform unauthorized actions affecting data confidentiality, integrity, or availability.

Potential impact on your site

04Site Impact

Users with low-privilege accounts can access, modify, or disrupt functionality they should not have permission to use.

Conditions required to exploit

05Prerequisites

Attacker must have a low-privilege account and trick a user into clicking a malicious link or visiting a crafted page.

Key dates

06Disclosure timeline

January 27, 2025 CVE published
April 28, 2026 Record updated

Related vulnerabilities

08Related CVE