GiveWP Stored XSS Vulnerability
CVE-2022-40211
4.8MEDIUM
What is CVE-2022-40211?
A cross-site scripting (XSS) vulnerability exists in the GiveWP plugin that can lead to stored XSS attacks. This vulnerability arises from improper neutralization of user input during web page generation. When exploited, attackers may inject malicious scripts that can execute in the context of authenticated users, leading to unauthorized data access and potential compromise of application integrity. Users of GiveWP versions up to 2.25.1 are particularly at risk and should take steps to mitigate this vulnerability.
Affected Version(s)
GiveWP <= 2.25.1