Shortcode Execution Vulnerability in GiveWP Plugin for WordPress
CVE-2026-85113
Key Information:
Badges
What is CVE-2026-85113?
The GiveWP plugin for WordPress, up to version 4.16.9, is susceptible to a vulnerability that allows unauthenticated users to execute arbitrary shortcodes. This occurs because the plugin fails to adequately remove shortcode delimiters from user-supplied input before rendering it on public pages. Moreover, the plugin's shortcode stripping mechanisms can be bypassed by nesting shortcodes, which further exposes the site to potential attacks. As a result, this vulnerability can lead to unauthorized access and manipulation of site content, posing significant security risks for WordPress users.
Affected Version(s)
GiveWP 4.13.2 < 4.16.9
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V3.1
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved