PT-2026-83072 · WordPress · Givewp
CVSS v3.1
6.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
GiveWP – Donation Plugin and Fundraising Platform versions prior to 4.14.5
Description
Stored Cross-Site Scripting (XSS) occurs via the 'give form' shortcode. The issue stems from insufficient input sanitization and output escaping of the
continue button title and display style shortcode attributes. Although these attributes are processed by the sanitize text field() function, they are not properly escaped when rendered in HTML data attributes. This allows authenticated attackers with Contributor-level access or higher to inject arbitrary web scripts into pages, which execute when a user visits the affected page.Recommendations
Update to version 4.14.5 or later.
Restrict the use of the
continue button title and display style attributes within the 'give form' shortcode until the update is applied.Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Givewp