Junglewise Threat Intelligence

CVE-2026-66690: GiveWP unauthenticated cross-site scripting

CVE-2026-66690 · Severity: high · CVSS 7.1 · Published 2026-08-06

Technologies: StellarWP GiveWP. Vendors: StellarWP.

Executive brief

GiveWP is a WordPress plugin for managing charitable donations and fundraising campaigns on websites. This vulnerability allows attackers to inject malicious scripts into pages without authentication, potentially stealing visitor data or hijacking user accounts. Sites running version 4.16.5 and earlier are affected and should upgrade immediately.

Technical details

This is an unauthenticated Cross-Site Scripting (XSS) vulnerability in GiveWP versions 4.16.5 and earlier. The vulnerability allows attackers to inject malicious JavaScript into the plugin without requiring authentication or privileged access. Exploitation requires user interaction (e.g., a visitor clicking a malicious link or visiting a crafted page). Successful exploitation enables attackers to steal visitor data, hijack accounts, or perform actions on behalf of affected users. The vulnerability was patched in version 4.16.5.1.

Affected products

  • StellarWP GiveWP <=4.16.5

Timeline

  • 2026-07-22: disclosed
  • 2026-07-31: patched: Version 4.16.5.1 released

References

Related threats