Executive brief
GiveWP is a popular WordPress plugin used by organizations to manage donations and fundraising campaigns. A security flaw allows users with 'Give Worker' permissions to inject malicious scripts into donation pages. When other users or administrators view these pages, the scripts could execute, potentially leading to unauthorized actions or data theft.
Technical details
The GiveWP plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) due to insufficient input sanitization and output escaping on the 'sequoia[introduction][image]' parameter. Authenticated attackers with 'Give Worker' level access or higher can inject arbitrary web scripts into the database. These scripts will execute in the context of any user's browser who visits the affected donation form or administrative page. The vulnerability exists in all versions up to and including 4.16.1. A patch is expected in subsequent releases to properly sanitize the affected metadata fields.
Affected products
- StellarWP GiveWP – Donation Plugin and Fundraising Platform <= 4.16.1
Timeline
- 2026-07-02: disclosed: Advisory published by Wordfence and NVD
References
- https://plugins.trac.wordpress.org/browser/give/tags/4.14.6/includes/admin/forms/class-metabox-form-data.php
- https://plugins.trac.wordpress.org/browser/give/tags/4.14.6/includes/formatting.php
- https://plugins.trac.wordpress.org/browser/give/tags/4.14.6/src/Views/Form/Templates/Sequoia/Sequoia.php
- https://plugins.trac.wordpress.org/browser/give/tags/4.14.6/src/Views/Form/Templates/Sequoia/sections/introduction.php
- https://plugins.trac.wordpress.org/browser/give/tags/4.16.0/includes/admin/forms/class-metabox-form-data.php
- https://plugins.trac.wordpress.org/browser/give/tags/4.16.0/includes/formatting.php
- https://plugins.trac.wordpress.org/browser/give/tags/4.16.0/src/Views/Form/Templates/Sequoia/Sequoia.php