Junglewise Threat Intelligence

CVE-2026-34900: GiveWP unauthenticated reflected XSS

CVE-2026-34900 · Severity: high · CVSS 7.1 · Published 2026-06-15

Technologies: StellarWP GiveWP. Vendors: StellarWP.

Executive brief

GiveWP is a popular WordPress plugin used by organizations to accept donations and manage fundraising campaigns. A security flaw in this plugin allows an attacker to inject malicious scripts into the website, which could lead to the theft of sensitive donor information, unauthorized redirects to malicious sites, or the takeover of administrative accounts if a site manager clicks a specially crafted link. This vulnerability can be exploited without needing a username or password, though it requires a user to interact with a malicious link.

Technical details

GiveWP is vulnerable to reflected Cross-Site Scripting (XSS) due to improper neutralization of user-supplied input during web page generation (CWE-79). The vulnerability exists in versions up to and including 4.14.2. An unauthenticated remote attacker can exploit this by tricking a user (such as a site administrator) into clicking a specially crafted link or visiting a malicious page. Successful exploitation allows the attacker to execute arbitrary JavaScript in the context of the victim's browser session, potentially leading to session hijacking or unauthorized actions. The issue is resolved in version 4.14.3.

Affected products

  • Liquid Web / StellarWP GiveWP <= 4.14.2

Timeline

  • 2026-03-12: other: Reported by HuajiHD
  • 2026-04-21: advisory: Initial Patchstack advisory published
  • 2026-06-15: disclosed: NVD publication date
  • 2026-04-21: patched: Patch released in version 4.14.3

References

Related threats