Bitcoin Donate Button WordPress Plugin Cross-Site Request Forgery Vulnerability

Vulnerability

A Cross-Site Request Forgery (CSRF) vulnerability exists in the Bitcoin Donate Button plugin for WordPress, affecting all versions through 1.0. The issue arises from inadequate nonce validation on the settings page, allowing unauthenticated attackers to alter the plugin's settings, such as donation addresses and display options. This can be achieved by tricking a site administrator into clicking a link that sends a forged request.

Impact

Exploitation of this vulnerability allows for unauthorized modification of the plugin's settings by an attacker, potentially leading to misdirected donations or altered display configurations on the site.

Added: Jan 28, 2026, 12:22 PM
Updated: Jan 28, 2026, 12:22 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
0.6
exploitability
7.0
remediation
0.0
relevance
2.6
threat
3.2
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.