GiveWP
cpe:2.3:a:givewp:give:*:*:*:*:wordpress:*:*, +1 more
- <= 4.13.0
A stored cross-site scripting vulnerability has been identified in the GiveWP Donation Plugin and Fundraising Platform for WordPress, affecting all versions through 4.13.0. The vulnerability arises from inadequate input sanitization and output escaping, allowing unauthenticated attackers to inject arbitrary web scripts into pages. These scripts execute when users access the compromised pages. Exploitation requires that avatars be enabled on the WordPress installation.
Exploitation of this vulnerability allows for stored cross-site scripting, where injected scripts are executed in the context of the user viewing the page.
To reproduce this vulnerability, upload a donation through the GiveWP plugin, ensuring that the 'name' field includes the injected script. After the donation is processed, the injected script will execute when the donor wall is viewed.
Users are advised to update the GiveWP Donation Plugin to version 4.13.1 or later.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.