Stored Cross-Site Scripting Vulnerability in GiveWP Donation Plugin for WordPress
CVE-2026-97643

6.4MEDIUM

What is CVE-2026-97643?

The GiveWP – Donation Plugin for WordPress is susceptible to Stored Cross-Site Scripting (XSS) due to inadequate input sanitization and output escaping in its givewp_campaign_grid shortcode. This vulnerability affects versions up to and including 4.17.0, allowing authenticated attackers with Contributor-level access or higher to inject malicious web scripts into pages. The core issue arises in the CampaignGridShortcode::parseAttributes() function, where user-supplied attributes such as filter_by, layout, sort_by, and order_by are not properly sanitized. This can lead to a scenario where the json_encode() function outputs data that includes single quotes, potentially breaking out of HTML attributes and executing harmful scripts whenever a user accesses a compromised page.

Affected Version(s)

GiveWP – Donation Plugin and Fundraising Platform 0 <= 4.17.0

References

CVSS V3.1

Score:
6.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Wordfence PRISM
.