WordPress · Givewp · CVE-2026-13704
**Name of the Vulnerable Software and Affected Versions**
GiveWP – Donation Plugin and Fundraising Platform versions prior to 4.16.2
**Description**
Insufficient input sanitization and output escaping allow authenticated attackers with Give Worker-level access or higher to perform Stored Cross-Site Scripting (XSS). This occurs via the `sequoia[introduction][image]` parameter, enabling the injection of arbitrary web scripts into pages that execute when accessed by other users.
**Recommendations**
Update GiveWP – Donation Plugin and Fundraising Platform to version 4.16.2 or later.
Restrict access to the `sequoia[introduction][image]` parameter for users with Give Worker-level permissions until the update is applied.