VYPR

Kudos Donations

by WordPress

Source repositories

CVEs (2)

  • CVE-2024-11685MedNov 28, 2024
    risk 0.40cvss 6.1epss 0.00

    The `Kudos Donations – Easy donations and payments with Mollie` plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of `add_query_arg` without appropriate escaping on the URL in all versions up to, and including, 3.2.9. This makes it possible…

  • CVE-2024-11684MedNov 28, 2024
    risk 0.33cvss 6.1epss 0.00

    The Kudos Donations – Easy donations and payments with Mollie plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 's' parameter in all versions up to, and including, 3.2.9 due to insufficient input sanitization and output escaping. This makes it…