CVE-2022-1396: Donorbox

Medium severity, CVSS 4.8. EPSS: 1% chance of exploitation in the next 30 days.

The Donorbox WordPress plugin before 7.1.7 does not sanitise and escape its Campaign URL settings before outputting it in an attribute, leading to a Stored Cross-Site Scripting issue even when the unfiltered_html capability is disallowed

Affected products

  • Donorbox Donorbox: before 7.1.7 (fixed in 7.1.7)

Published 2022-04-25. Last modified 2026-06-17.