Donate Me
Donate Me has 2 disclosed vulnerabilities in the WordSec catalog, reported between 2024 and 2025; all 2 are fixed as of September 2026. Their average CVSS score is 6.3, and the most serious one scores 6.4 out of 10.
The most common weakness is Cross-Site Request Forgery (CSRF), behind 1 of the records (50%). Other recurring categories include Cross-Site Scripting.
Every one of the 2 issues recorded for Donate Me has a vendor fix available, so running the current release closes all known holes.
2 independent researchers contributed these findings, one record each. Donate Me is installed on roughly 10 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.0.4.
CVE-2025-31778Donate Me <= 1.2.5 - Authenticated (Subscriber+) Stored Cross-Site Scripting
Read the full analysisVulnerability Records

Donate Me
Author
raphaelheide
Adds PayPal donation with Donate Me shortcode in any place of your website. In the settings, add your PayPal email or Merchant ID. Supported currencies: Australian Dollars (AUD), Brazilian Real (BRL), Canadian Dollars (CAD), Czech Koruna (CZK), Danish Krone (DKK), Euro (EUR), Hong Kong Dollar (HKD), Hungarian Forint (HUF), Israeli New Shekel (ILS), Japanese Yen (JPY), Malaysian Ringgit (MYR), Mexican Peso (MXN), Norwegian Krone (NOK), New Zealand Dollar (NZD), Philippine Peso (PHP), Polish Zloty (PLN), Pounds Sterling (GBP), South African Rand (ZAR), Russian Ruble (RUB), Singapore Dollar (SGD), Swedish Krona (SEK), Swiss Franc (CHF), Taiwan New Dollar (TWD), Thai Baht (THB), Turkish Lira (TRY), U.S. Dollars (USD). Multiple buttons and styles. Choose your button text, color, and text color. Choose button alignment. Live preview in settings. Security Version 1.3.0 adds: – Nonce verification on settings save (CSRF protection) – Input sanitization with WordPress sanitize_* functions – Output escaping with esc_html / esc_attr / esc_url – Currency and position allowlist validation – Fixed ZAF -> ZAR currency code for South African Rand
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C