Executive brief
GiveWP, a popular WordPress plugin used for managing online donations, is vulnerable to a security flaw that allows attackers to inject malicious scripts into the website. If a site administrator or visitor clicks a specially crafted link, the attacker could potentially steal session information, redirect users to malicious sites, or perform unauthorized actions on the website. This could lead to a loss of trust from donors and potential compromise of the site's administrative interface.
Technical details
A DOM-based Cross-Site Scripting (XSS) vulnerability exists in the GiveWP plugin for WordPress (versions up to and including 4.14.5). The flaw stems from improper neutralization of user-supplied input during web page generation, specifically within the Document Object Model (DOM) environment. An unauthenticated remote attacker can exploit this by tricking a user into interacting with a malicious link or crafted page. Successful exploitation allows the execution of arbitrary JavaScript in the context of the victim's browser session, which can lead to session hijacking or unauthorized data access. The issue is resolved in version 4.14.6.
Affected products
- Liquid Web / StellarWP GiveWP n/a through 4.14.5
Timeline
- 2026-04-16: other: Reported by thevietronin
- 2026-05-16: advisory: Patchstack advisory published
- 2026-06-01: disclosed: NVD publication date