The Donation Button Project maintains a narrowly scoped donation-collection plugin or widget, a modestly represented component in the vulnerability landscape that handles payment or contribution flows on web platforms. Treat this as a focused vendor profile; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Donation Button Project over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-4004MEDIUM The Donation Button WordPress plugin through 4.0.0 does not properly check for privileges and nonce tokens in its "donation_button_twilio_send_test_sms" AJAX action, which may allo | Dec 12, 2022 | 4.3 | 18 | NO | NO |
CVE-2022-4005MEDIUM The Donation Button WordPress plugin through 4.0.0 does not sanitize and escapes some parameters, which could allow users with a role as low as Contributor to perform Cross-Site Sc | Dec 12, 2022 | 5.4 | 15 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Donation Button Project.
Media articles that mention a CVE ID that affects a product developed by Donation Button Project — matched by CVE ID, not by vendor name.