Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-54267 | The Donation Forms by Charitable plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 1.7.0.12 due to insufficient restriction on the 'update_core_user' function. This makes it possible for unauthenticated attackers to specify their user role by supplying the 'role' parameter during a registration. |
Wed, 08 Apr 2026 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Donation Forms by Charitable <= 1.7.0.12 - Unauthenticated Privilege Escalation |
Thu, 06 Feb 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-04-08T16:52:44.943Z
Reserved: 2023-08-17T18:17:49.199Z
Link: CVE-2023-4404
Updated: 2024-08-02T07:24:04.702Z
Status : Modified
Published: 2023-08-23T02:15:08.887
Modified: 2026-04-08T18:18:14.577
Link: CVE-2023-4404
No data.
OpenCVE Enrichment
No data.
EUVD