s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

CVE-2023-47550

📛 CVE Title

WordPress Donations Made Easy – Smart Donations Plugin <= 4.0.12 is vulnerable to Cross Site Scripting (XSS)

Description

Cross-Site Request Forgery (CSRF) vulnerability in RedNao Donations Made Easy – Smart Donations allows Stored XSS.This issue affects Donations Made Easy – Smart Donations: from n/a through 4.0.12.

Overview

State
PUBLISHED
Assigner (CNA)
Patchstack
CVSS severity
HIGH
CVSS score
CVSS 7.1 / 10 7.1 7.1 / 10
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
Effective score
7.1 / 10 HIGH source: CNA overview
CWE(s)
CWE-352
Reserved
2023-11-06
Published
2023-11-14 21:03 UTC
Last updated
2026-04-28 18:08 UTC
Source
https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2023/47xxx/CVE-2023-47550.json
Linked Threat
CVE-2023-47550 — Donations Made Easy – Smart Donations <= 4.0.12 - Authenticated (Contributor+) Stored Cross-Site Scripting

NVD triage scoring NVD CVE 2.0

Layer NVD adds on top of the CNA's CVE record — published / last-modified timestamps, exploitability / impact subscores, and the FIRST.org EPSS probability that this CVE will be exploited in the wild in the next 30 days.

NVD published
2023-11-14 20:15:08 UTC
NVD last modified
2026-06-17 06:32:53 UTC
NVD CVSS v3.1
CVSS 7.1 / 10 7.1 7.1 / 10 HIGH source: audit@patchstack.com
NVD CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
Exploitability subscore
2.8 / 10
Impact subscore
3.7 / 10
EPSS score
0.0022 (probability of exploitation in next 30 days)
EPSS percentile
12.65% vs all CVEs — higher = more likely to be exploited, as of 2026-07-26

NVD / KEV / EPSS data refreshed 2026-07-27 08:06 UTC. Re-run the 🛰 Backfill from NVD button above to refresh.

European Union Vulnerability Database ENISA EUVD

ENISA's official EU repository for curated vulnerability intelligence. Carries a separate identifier (EUVD-YYYY-NNNN) and frequently exposes an earlier-published description + CVSS than NVD does.

EUVD ID
EUVD-2023-51661
Assigner
Patchstack
Published
Nov 14, 2023, 8:03:38 PM
Updated
Apr 28, 2026, 4:08:50 PM
EUVD base score (CVSS 3.1)
7.1 / 10
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
EUVD-reported EPSS
0.1400
Vendors
RedNao
Products
Donations Made Easy – Smart Donations (n/a ≤4.0.12)
Aliases
GHSA-5xr2-69wj-6x93

ENISA description: Cross-Site Request Forgery (CSRF) vulnerability in RedNao Donations Made Easy – Smart Donations allows Stored XSS.This issue affects Donations Made Easy – Smart Donations: from n/a through 4.0.12.

EUVD references (1)

Affected products (1)

VendorProductVersionsPlatforms
RedNao Donations Made Easy – Smart Donations n/a (affected)

Affected products — CPE 2.3 (1) NVD

NVD's normalized CPE 2.3 matchers, used by vendor tools (vulnerability scanners, asset managers) for automated detection. Compare with the CNA's free-text "Affected products" section above.

  • cpe:2.3:a:rednao:donations_made_easy_-_smart_donations:*:*:*:*:*:wordpress:*:*

Vendor references (1)

References embedded in the original CVE record by the assigning CNA.

MITRE references (1) cveawg.mitre.org

Pulled from MITRE's CVE Services API by the 🛰 Backfill from MITRE button.

Web references (0)

DuckDuckGo results ranked by threat-intel / vendor advisory domains. Generated by the 🔎 Find references (web) button above — same flow as the Remediations search.

No web references attached yet.

NVD-tagged references (2)

Reference list NVD curates from the CNA record, vendor advisories, and third-party reports. The tag chips below are NVD's analyst-assigned categories.

Indicators (2)

IOCs linked to the auto-promoted Threat row.

TypeValueVirusTotalAttached
domain xss.this no local data 2026-05-18 21:20 UTC
cve CVE-2023-47550 no local data 2026-06-06 14:53 UTC

Flagged vendors

    Remediations (22)

    Remediations are stored against the linked Threat row; the list below is deduplicated across both pages.

    • web:www.microsoft.com

      Security Update Guide Notifications Microsoft's free Security Update Guide Notifications provide links to security-related software updates and notification of re-released security updates. These notifications are sent via email throughout the month as needed.

      2026-06-27 10:57 UTC
    • web:www.oracle.com

      This Critical Patch Update contains 318 new security patches across the product families listed below. Please note that an MOS note summarizing the content of this Critical Patch Update and other Oracle Software Security Assurance activities is located at January 2025 Critical Patch Update: Executive Summary and Analysis.

      2026-06-27 10:57 UTC
    • web:www.cisco.com

      This document describes a list of software versions that have incorporated fixes for Cisco IOS® XE Software Web UI Cisco bug ID CSCwh87343.

      2026-06-27 10:57 UTC
    • web:www.oracle.com

      Oracle Critical Patch Update Advisory - July 2025 Description A Critical Patch Update is a collection of patches for multiple security vulnerabilities. These patches address vulnerabilities in Oracle code and in third party components included in Oracle products. These patches are usually cumulative, but each advisory describes only the security patches added since the previous Critical Patch ...

      2026-06-27 10:57 UTC
    • web:github.com

      CVEfixes: Automated Collection of Vulnerabilities and Their Fixes from Open-Source Software - secureIT-project/CVEfixes

      2026-06-27 10:57 UTC
    • Wordfence remediation: Donations Made Easy – Smart Donations
      Wordfence

      No known patch available. Please review the vulnerability's details in depth and employ mitigations based on your organization's risk tolerance. It may be best to uninstall the affected software and find a replacement.

      2026-06-06 14:53 UTC
    • web:www.securityweek.com

      Microsoft has announced mitigations for CVE -2026-45585, a BitLocker bypass triggered via FsTx in Windows Recovery.

      2026-05-22 07:33 UTC
    • web:www.ibm.com

      Updates listed within IBM Fix Central without a key symbol are generally available for installation subject to the terms of the applicable license agreement. Any copying, reproduction, distribution, or installation of code, other than as expressly authorized by IBM, is prohibited.

      2026-05-22 07:33 UTC
    • web:www.oracle.com

      Critical Security Patch Updates Critical Security Patch Updates provide security patches for supported Oracle on-premises products. A Critical Security Patch Update provides targeted, high-priority security fixes in a smaller, more focused format, making them easier to apply with minimal disruption.

      2026-05-22 07:33 UTC
    • web:krebsonsecurity.com

      October's Patch Tuesday also marks the final month that Microsoft will ship security updates for Windows 10 systems.

      2026-05-22 07:33 UTC
    • web:support.servicenow.com

      Overview The advisories below document publicly disclosed Common Vulnerabilities and Exposures ( CVEs ) in the Now Platform by ServiceNow. Because ServiceNow uses various methods to communicate vulnerability information, patches, and other fixes, customers should review family, security patch , and hotfix release notes, which are available at https://docs.servicenow.com, for a complete list of ...

      2026-05-22 07:33 UTC
    • web:nvd.nist.gov

      Vulnerabilities All vulnerabilities in the NVD have been assigned a CVE identifier and thus, abide by the definition below. CVE defines a vulnerability as: "A weakness in the computational logic (e.g., code) found in software and hardware components that, when exploited, results in a negative impact to confidentiality, integrity, or availability. Mitigation of the vulnerabilities in this ...

      2026-05-22 07:33 UTC
    • web:www.esri.com

      Key highlights The ArcGIS Server Security 2025 update 2 is available This patch resolves 10 Medium severity vulnerabilities This security patch is cumulative, and includes fixes provided in the ArcGIS Server Security 2025 update 1.

      2026-05-22 03:50 UTC
    • web:blog.qualys.com

      This Critical Patch Update for Oracle Communications Applications received 64 security patches. Out of these, 46 vulnerabilities can be exploited over a network without user credentials. CVE -2025-6965, CVE -2024-37371, and CVE -2025-49796 in different products of Oracle Communications Applications have critical severity ratings.

      2026-05-22 03:50 UTC
    • web:docs.oracle.com

      Oracle Critical Patch Update (CPU) July 2025 for Oracle Java SE Services: Java Management Release Date: July 15, 2025

      2026-05-22 03:50 UTC
    • web:oracle-base.com

      The OPatch utility doesn't let you re-apply a patch already present, so it's quite easy to simplify the process by having a very similar process each quarter. Once I've got all the patches, I write a patching script for each product. For the database this includes OPatch and the latest database patches.

      2026-05-22 03:50 UTC
    • web:portal.msrc.microsoft.com

      The Security Update Guide provides information on the latest Microsoft security updates, helping users understand and address potential vulnerabilities effectively.

      2026-05-22 03:50 UTC
    • web:www.cve.org

      At cve .org, we provide the authoritative reference method for publicly known information-security vulnerabilities and exposures

      2026-05-22 03:50 UTC
    • web:access.redhat.com

      Learn about our open source products, services, and company. You are here

      2026-05-22 03:50 UTC
    • web:www.forbes.com

      Mitigation Measures To Take If Patching Isn't Possible Assuming a patch can't be promptly applied, what can be done to mitigate risk? There are several important measures to keep in mind:

      2026-05-22 03:50 UTC
    • web:www.securityweek.com

      Oracle on Tuesday announced the release of 481 new security patches as part of its April 2026 Critical Patch Update (CPU). Across the 28 product families that received security updates, more than 300 patches address vulnerabilities that are remotely exploitable without authentication.

      2026-05-22 03:50 UTC
    • web:www.tenable.com

      Oracle addresses 165 CVEs in its third quarterly update of 2025 with 309 patches, including nine critical updates.

      2026-05-22 03:50 UTC

    AI Forensic Analysis

    Only Available for Registered Users. Sign in to view.

    Raw JSON

    The full cvelistV5 record. Download as CVE-2023-47550.json.

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-02T21:09:37.433Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "vdb-entry",
                  "x_transferred"
                ],
                "url": "https://patchstack.com/database/vulnerability/smart-donations/wordpress-donations-made-easy-smart-donations-plugin-4-0-12-cross-site-scripting-xss-vulnerability-2?_s_id=cve"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2023-47550",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-08-28T15:00:51.738095Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-08-28T15:09:59.857Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "collectionURL": "https://wordpress.org/plugins",
              "defaultStatus": "unaffected",
              "packageName": "smart-donations",
              "product": "Donations Made Easy \u2013 Smart Donations",
              "vendor": "RedNao",
              "versions": [
                {
                  "lessThanOrEqual": "4.0.12",
                  "status": "affected",
                  "version": "n/a",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "user": "00000000-0000-4000-9000-000000000000",
              "value": "thiennv (Patchstack Alliance)"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Cross-Site Request Forgery (CSRF) vulnerability in RedNao Donations Made Easy \u2013 Smart Donations allows Stored XSS.<p>This issue affects Donations Made Easy \u2013 Smart Donations: from n/a through 4.0.12.</p>"
                }
              ],
              "value": "Cross-Site Request Forgery (CSRF) vulnerability in RedNao Donations Made Easy \u2013 Smart Donations allows Stored XSS.This issue affects Donations Made Easy \u2013 Smart Donations: from n/a through 4.0.12."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-592",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-592 Stored XSS"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "LOW",
                "baseScore": 7.1,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "LOW",
                "integrityImpact": "LOW",
                "privilegesRequired": "NONE",
                "scope": "CHANGED",
                "userInteraction": "REQUIRED",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-352",
                  "description": "CWE-352 Cross-Site Request Forgery (CSRF)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-04-28T16:08:50.102Z",
            "orgId": "21595511-bba5-4825-b968-b78d1f9984a3",
            "shortName": "Patchstack"
          },
          "references": [
            {
              "tags": [
                "vdb-entry"
              ],
              "url": "https://patchstack.com/database/vulnerability/smart-donations/wordpress-donations-made-easy-smart-donations-plugin-4-0-12-cross-site-scripting-xss-vulnerability-2?_s_id=cve"
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "title": "WordPress Donations Made Easy \u2013 Smart Donations Plugin <= 4.0.12 is vulnerable to Cross Site Scripting (XSS)",
          "x_generator": {
            "engine": "Vulnogram 0.1.0-dev"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "21595511-bba5-4825-b968-b78d1f9984a3",
        "assignerShortName": "Patchstack",
        "cveId": "CVE-2023-47550",
        "datePublished": "2023-11-14T20:03:38.080Z",
        "dateReserved": "2023-11-06T11:10:24.704Z",
        "dateUpdated": "2026-04-28T16:08:50.102Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }