CVE-2025-13001
EUVD-2025-20018902.12.2025, 06:15
The donation WordPress plugin through 1.0 does not sanitize and escape a parameter before using it in a SQL statement, allowing high privilege users, such as admin to perform SQL injection attacks
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| kieranoshea | donations | 𝑥 ≤ 1.0 |
𝑥
= Vulnerable software versions