WordPress Plugin Vulnerabilities
GiveWP < 4.16.3 - GiveWP Worker+ Stored XSS via Donation Form Template Settings
Description
The plugin does not escape a donation-form template setting before outputting it in an HTML attribute, allowing users with the GiveWP Worker role and above to inject arbitrary web scripts that execute on the public donation form viewed by any visitor.
Proof of Concept
Affects Plugins
References
CVE
Classification
Type
XSS
OWASP top 10
CWE
CVSS
Miscellaneous
Original Researcher
Meher Sudhakar Abbireddi
Submitter
Meher Sudhakar Abbireddi
Verified
Yes
WPVDB ID
Timeline
Publicly Published
2026-07-10 (about 21 days ago)
Added
2026-07-10 (about 20 days ago)
Last Updated
2026-07-10 (about 20 days ago)