Click & Pledge CONNECT Security & Risk Analysis

wordpress.org/plugins/click-pledge-connect

 

100 active installs v25.09000000-WP6.8.2 PHP 5.6+ WP 5.2+ Updated Sep 16, 2025
click-pledgedonation-formsfundraisingnonprofitsalesforce-integration
93
A · Safe
CVEs total2
Unpatched0
Last CVEJul 1, 2025
Safety Verdict

Is Click & Pledge CONNECT Safe to Use in 2026?

Generally Safe

Score 93/100

Click & Pledge CONNECT has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.

2 known CVEsLast CVE: Jul 1, 2025Updated 8mo ago
Risk Assessment

The plugin 'click-pledge-connect' v25.09000000-WP6.8.2 exhibits a mixed security posture. On the positive side, the static analysis indicates a strong adherence to secure coding practices, with 100% of AJAX handlers and REST API routes protected by authentication checks. The vast majority of SQL queries (99%) utilize prepared statements, and a significant portion of outputs (83%) are properly escaped, which are excellent indicators. However, there are several areas of concern. The taint analysis reveals 4 flows with unsanitized paths, including 2 of high severity, suggesting potential vulnerabilities where user input might not be adequately validated before being used in sensitive operations. Additionally, the presence of 2 file operations and the bundling of a library (DataTables) could introduce risks if not managed carefully or if the library is outdated. The vulnerability history is particularly concerning, with 2 previously discovered CVEs, one critical and one high, both related to SQL injection. While the current version shows no unpatched CVEs, the historical pattern of SQL injection vulnerabilities, especially critical ones, indicates a recurring weakness in how user input is handled. The last vulnerability being in July 2025 is also a recent occurrence. Overall, while the plugin implements many good security practices, the identified taint flows and historical vulnerability patterns necessitate careful review and ongoing vigilance to mitigate potential risks.

Key Concerns

  • High severity unsanitized taint flows
  • Unsanitized taint flows
  • Historical critical SQL injection CVE
  • Historical high SQL injection CVE
  • Bundled library
  • File operations present
Vulnerabilities
2 published

Click & Pledge CONNECT Security Vulnerabilities

CVEs by Year

2 CVEs in 2025
2025
Patched Has unpatched

Severity Breakdown

Critical
1
High
1

2 total CVEs

CVE-2025-28983critical · 9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Click & Pledge Connect <= 25.04010101-WP6.8 - Unauthenticated SQL Injection to Privilege Escalation

Jul 1, 2025 Patched in 25.07000000-WP6.8.1 (10d)
CVE-2025-32550high · 7.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Click & Pledge Connect Plugin <= 2.24080000-WP6.6.1 - Unauthenticated SQL Injection

Apr 9, 2025 Patched in 2.24120000-WP6.7.1 (8d)
Version History

Click & Pledge CONNECT Release Timeline

v25.09000000-WP6.8.2Current
v25.07000002-WP6.8.2
v25.07000001-WP6.8.1
v25.07000000-WP6.8.1
v25.04010101-WP6.81 CVE
v02.2301020000-WP6.1.11 CVE
v02.2112010000-WP5.8.21 CVE
v02.2112000000-WP5.8.21 CVE
v02.2101000000-WP5.61 CVE
v02.2002000200-WP5.3.21 CVE
v02.1912000103-WP5.3.11 CVE
v2.24120000-WP6.7.11 CVE
v2.24080000-WP6.6.12 CVEs
v2.23110000-WP6.4.12 CVEs
v2.00000000000000002 CVEs
Code Analysis
Analyzed Mar 16, 2026

Click & Pledge CONNECT Code Analysis

Dangerous Functions
0
Raw SQL Queries
1
101 prepared
Unescaped Output
49
237 escaped
Nonce Checks
20
Capability Checks
2
File Operations
2
External Requests
0
Bundled Libraries
1

Bundled Libraries

DataTables

SQL Query Safety

99% prepared102 total queries

Output Escaping

83% escaped286 total outputs
Data Flows · Security
4 unsanitized

Data Flow Analysis

20 flows4 with unsanitized paths
cnps_addform (FormAdd.php:8)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Click & Pledge CONNECT Attack Surface

Entry Points21
Unprotected0

AJAX Handlers 18

authwp_ajax_getCnPUserChannelListclickandpledge_form.php:260
noprivwp_ajax_getCnPUserChannelListclickandpledge_form.php:261
authwp_ajax_CNPCF_friendlynameclickandpledge_form.php:600
noprivwp_ajax_CNPCF_friendlynameclickandpledge_form.php:601
authwp_ajax_CNPCF_cnpaccountidclickandpledge_form.php:602
noprivwp_ajax_CNPCF_cnpaccountidclickandpledge_form.php:603
authwp_ajax_CNPCF_cnpgroupnameclickandpledge_form.php:604
noprivwp_ajax_CNPCF_cnpgroupnameclickandpledge_form.php:605
authwp_ajax_CNPCF_cnpchnlgroupnameclickandpledge_form.php:606
noprivwp_ajax_CNPCF_cnpchnlgroupnameclickandpledge_form.php:607
authwp_ajax_cfcnp_verify_accountclickandpledge_form.php:608
noprivwp_ajax_cfcnp_verify_accountclickandpledge_form.php:609
authwp_ajax_cfcnp_refresh_accountclickandpledge_form.php:610
authwp_ajax_cfcnp_load_campaignsclickandpledge_form.php:611
authwp_ajax_cfcnp_load_formsclickandpledge_form.php:612
authwp_ajax_cfcnp_load_edit_campaignsclickandpledge_form.php:613
authwp_ajax_cfcnp_get_edit_formsclickandpledge_form.php:614
authwp_ajax_cfcnp_get_channelsclickandpledge_form.php:615

Shortcodes 3

[CnPConnect] clickandpledge_form.php:1382
[CnP.Form] clickandpledge_form.php:1383
[CnP.pledgeTV] clickandpledge_form.php:1384
WordPress Hooks 14
actionadmin_noticesclickandpledge_form.php:67
actionplugins_loadedclickandpledge_form.php:247
actionwp_default_scriptsclickandpledge_form.php:251
actionadmin_menuclickandpledge_form.php:256
filternav_menu_css_classclickandpledge_form.php:257
actionadmin_initclickandpledge_form.php:258
actionview_formsdetailsclickandpledge_form.php:366
filternav_menu_css_classclickandpledge_form.php:367
filterset-screen-optionclickandpledge_form.php:410
filtersgs_whitelist_wp_contentclickandpledge_form.php:411
actionadmin_enqueue_scriptsclickandpledge_form.php:1061
actionwp_enqueue_scriptsclickandpledge_form.php:1063
actionwp_footerclickandpledge_form.php:1142
actionadmin_footerclickandpledge_form.php:1422
Maintenance & Trust

Click & Pledge CONNECT Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedSep 16, 2025
PHP min version5.6
Downloads10K

Community Trust

Rating0/100
Number of ratings0
Active installs100
Developer Profile

Click & Pledge CONNECT Developer Profile

ClickandPledge

5 plugins · 200 total installs

93
trust score
Avg Security Score
98/100
Avg Patch Time
27 days
View full developer profile
Detection Fingerprints

How We Detect Click & Pledge CONNECT

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/click-pledge-connect/css/cnp_connect.css/wp-content/plugins/click-pledge-connect/js/cnp_connect.js/wp-content/plugins/click-pledge-connect/js/cp_donate.js
Script Paths
/wp-content/plugins/click-pledge-connect/js/cnp_connect.js/wp-content/plugins/click-pledge-connect/js/cp_donate.js
Version Parameters
click-pledge-connect/css/cnp_connect.css?ver=click-pledge-connect/js/cnp_connect.js?ver=click-pledge-connect/js/cp_donate.js?ver=

HTML / DOM Fingerprints

CSS Classes
cnp-form-container
Data Attributes
data-cnp-campaign-id
JS Globals
cnp_donate_obj
Shortcode Output
[cp_connect_form]
FAQ

Frequently Asked Questions about Click & Pledge CONNECT