The `Kudos Donations – Easy donations and payments with Mollie` plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of `add_query_arg` without appropriate escaping on the URL in all versions up to, and including, 3.2.9. This makes it possible for unauthenticated attackers to inject arbitrary web scripts that execute if they can successfully trick a user into performing an action, such as clicking on a specially crafted link.
History

Wed, 16 Jul 2025 00:45:00 +0000

Type Values Removed Values Added
First Time appeared Iseard
Iseard kudos Donations
CPEs cpe:2.3:a:iseard:kudos_donations:*:*:*:*:*:wordpress:*:*
Vendors & Products Iseard
Iseard kudos Donations

Thu, 28 Nov 2024 13:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 28 Nov 2024 09:00:00 +0000

Type Values Removed Values Added
Description The `Kudos Donations – Easy donations and payments with Mollie` plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of `add_query_arg` without appropriate escaping on the URL in all versions up to, and including, 3.2.9. This makes it possible for unauthenticated attackers to inject arbitrary web scripts that execute if they can successfully trick a user into performing an action, such as clicking on a specially crafted link.
Title Kudos Donations – Easy donations and payments with Mollie <= 3.2.9 - Reflected Cross-Site Scripting via 'add_query_arg'
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published: 2024-11-28T08:47:34.138Z

Updated: 2024-11-28T12:25:17.781Z

Reserved: 2024-11-25T15:59:25.111Z

Link: CVE-2024-11685

cve-icon Vulnrichment

Updated: 2024-11-28T12:24:56.977Z

cve-icon NVD

Status : Analyzed

Published: 2024-11-28T09:15:04.950

Modified: 2025-07-16T00:34:17.220

Link: CVE-2024-11685

cve-icon Redhat

No data.