PT-2026-83072 · WordPress · Givewp

·

CVE-2026-5510

·

Published

2026-08-28

·

Updated

2026-08-28

CVSS v3.1

6.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions GiveWP – Donation Plugin and Fundraising Platform versions prior to 4.14.5
Description Stored Cross-Site Scripting (XSS) occurs via the 'give form' shortcode. The issue stems from insufficient input sanitization and output escaping of the continue button title and display style shortcode attributes. Although these attributes are processed by the sanitize text field() function, they are not properly escaped when rendered in HTML data attributes. This allows authenticated attackers with Contributor-level access or higher to inject arbitrary web scripts into pages, which execute when a user visits the affected page.
Recommendations Update to version 4.14.5 or later. Restrict the use of the continue button title and display style attributes within the 'give form' shortcode until the update is applied.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-5510

Affected Products

Givewp