WordPress · Givewp · CVE-2026-14987
**Name of the Vulnerable Software and Affected Versions**
GiveWP – Donation Plugin and Fundraising Platform versions prior to 4.16.4
**Description**
Insufficient input sanitization and output escaping allow authenticated attackers with give worker-level access and above to perform Stored Cross-Site Scripting. The issue occurs when the `twitter message` Sequoia Template Setting is used, allowing the injection of arbitrary web scripts. These scripts execute when a donor clicks the Share on Twitter button on the Sequoia donation confirmation view, as the unescaped `twitter message` value is evaluated within a JavaScript template literal.
**Recommendations**
Update GiveWP – Donation Plugin and Fundraising Platform to version 4.16.4 or later.