Junglewise Threat Intelligence

CVE-2026-13704: StellarWP GiveWP Stored XSS in Sequoia template image parameter

CVE-2026-13704 · Severity: medium · CVSS 6.4 · Published 2026-07-02

Technologies: StellarWP GiveWP. Vendors: StellarWP.

Executive brief

GiveWP is a popular WordPress plugin used by organizations to manage donations and fundraising campaigns. A security flaw allows users with 'Give Worker' permissions to inject malicious scripts into donation pages. When other users or administrators view these pages, the scripts could execute, potentially leading to unauthorized actions or data theft.

Technical details

The GiveWP plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) due to insufficient input sanitization and output escaping on the 'sequoia[introduction][image]' parameter. Authenticated attackers with 'Give Worker' level access or higher can inject arbitrary web scripts into the database. These scripts will execute in the context of any user's browser who visits the affected donation form or administrative page. The vulnerability exists in all versions up to and including 4.16.1. A patch is expected in subsequent releases to properly sanitize the affected metadata fields.

Affected products

  • StellarWP GiveWP – Donation Plugin and Fundraising Platform <= 4.16.1

Timeline

  • 2026-07-02: disclosed: Advisory published by Wordfence and NVD

References

Related threats