Executive brief
GiveWP, a popular WordPress plugin used for managing donations and fundraising, contains a security flaw that allows users with 'Author' level permissions or higher to inject malicious scripts into website pages. These scripts execute automatically whenever a visitor views the affected page, potentially leading to unauthorized actions or data theft. This could compromise the integrity of the fundraising platform and the security of its visitors.
Technical details
The GiveWP plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) due to insufficient input sanitization and output escaping in the CampaignCommentsShortcode::parseAttributes() and BlockRenderController::render() functions. Specifically, the 'blockId' value is interpolated directly into a single-quoted HTML attribute without using the esc_attr() function. This allows authenticated attackers with author-level permissions or higher to inject arbitrary web scripts into pages. These scripts will execute in the context of any user who visits the compromised page. The vulnerability affects all versions up to and including 4.16.0.
Affected products
- StellarWP GiveWP – Donation Plugin and Fundraising Platform up to, and including, 4.16.0
Timeline
- 2026-07-01: disclosed: Initial publication of the CVE record.
References
- https://plugins.trac.wordpress.org/browser/give/tags/4.16.0/src/Campaigns/Actions/RegisterCampaignShortcodes.php
- https://plugins.trac.wordpress.org/browser/give/tags/4.16.0/src/Campaigns/Blocks/CampaignComments/Controller/BlockRenderController.php
- https://plugins.trac.wordpress.org/browser/give/tags/4.16.0/src/Campaigns/Blocks/CampaignComments/render.php
- https://plugins.trac.wordpress.org/browser/give/tags/4.16.0/src/Campaigns/Shortcodes/CampaignCommentsShortcode.php
- https://plugins.trac.wordpress.org/browser/give/tags/4.16.0/src/Campaigns/Shortcodes/CampaignCommentsShortcode.php
- https://plugins.trac.wordpress.org/browser/give/trunk/src/Campaigns/Actions/RegisterCampaignShortcodes.php
- https://plugins.trac.wordpress.org/browser/give/trunk/src/Campaigns/Blocks/CampaignComments/Controller/BlockRenderController.php