Executive brief
Charitable is a WordPress plugin used to manage fundraising campaigns. The plugin fails to properly sanitize the ALT text field of campaign images, allowing campaign managers to inject malicious JavaScript code. When visitors view the campaign page, the injected code executes in their browsers, potentially enabling attackers to steal session cookies, hijack accounts, or deface campaign pages.
Technical details
This is a Stored Cross-Site Scripting (XSS) vulnerability in the campaign image ALT text field. The vulnerable component uses only wp_strip_all_tags() to process the ALT text before outputting it into an HTML img attribute, which does not escape double quotes. An attacker with campaign-manager or administrator role can inject a payload like 123123"onmouseover=alert(999) that breaks out of the alt attribute and injects an event handler. The payload executes when any visitor hovers over the image on the front-end campaign page. No user interaction from the victim is required beyond viewing the campaign page; the vulnerability is triggered automatically upon page load or hover. The fix is available in version 1.8.5.3 and later.
Affected products
- Charitable Charitable before 1.8.5.3
Timeline
- 2026-07-23: disclosed
- 2026-07-23: patched: Fixed in version 1.8.5.3
- 2026-08-02: advisory