Junglewise Threat Intelligence

CVE-2026-14987: StellarWP GiveWP Stored XSS in Sequoia Template Setting

CVE-2026-14987 · Severity: medium · CVSS 6.4 · Published 2026-07-16

Technologies: StellarWP GiveWP. Vendors: StellarWP.

Executive brief

GiveWP is a popular WordPress plugin used by organizations to manage donations and fundraising campaigns. A security flaw allows staff members with 'worker' level access to inject malicious scripts into donation confirmation pages. These scripts execute when a donor interacts with the 'Share on Twitter' button, potentially allowing the attacker to hijack user sessions or perform unauthorized actions on behalf of the donor.

Technical details

The GiveWP plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) in versions up to and including 4.16.3. The vulnerability exists within the 'twitter_message' Sequoia Template Setting due to insufficient input sanitization and output escaping. Authenticated attackers with 'give worker' level permissions or higher can inject arbitrary web scripts into the database. These scripts are subsequently executed in the context of a donor's browser when they click the 'Share on Twitter' button on the Sequoia donation confirmation view, as the unescaped value is evaluated inside a JavaScript template literal. Users should update to a version past 4.16.3 to mitigate this risk.

Affected products

  • StellarWP GiveWP – Donation Plugin and Fundraising Platform up to, and including, 4.16.3

Timeline

  • 2026-07-16: disclosed: CVE published by Wordfence and NVD

References

Related threats