Executive brief
GiveWP is a popular WordPress plugin used by organizations to accept donations and manage fundraising campaigns. A security flaw allows an unauthenticated attacker to inject malicious scripts into the website, which could lead to the theft of sensitive donor information, unauthorized redirects to malicious sites, or the defacement of the donation platform. This could significantly damage an organization's reputation and compromise the security of its supporters.
Technical details
A Cross-Site Scripting (XSS) vulnerability exists in the GiveWP plugin for WordPress due to improper neutralization of input during web page generation (CWE-79). The flaw allows an unauthenticated remote attacker to inject arbitrary web scripts or HTML payloads. Exploitation requires a victim (typically a site administrator or visitor) to interact with a malicious link or crafted page. Successful exploitation can lead to session hijacking, unauthorized actions in the context of the victim's browser, or redirection to malicious domains. The issue is resolved in version 4.16.4.
Affected products
- Nexcess / StellarWP GiveWP <= 4.16.3
Timeline
- 2026-07-03: other: Reported by researcher luc
- 2026-07-27: disclosed: Vulnerability disclosed by Patchstack
- 2026-07-27: patched: Patch released in version 4.16.4