Stored Cross-Site Scripting Vulnerability in GiveWP Donation Plugin for WordPress
CVE-2026-97643
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 10 October 2026
What is CVE-2026-97643?
The GiveWP β Donation Plugin for WordPress is susceptible to Stored Cross-Site Scripting (XSS) due to inadequate input sanitization and output escaping in its givewp_campaign_grid shortcode. This vulnerability affects versions up to and including 4.17.0, allowing authenticated attackers with Contributor-level access or higher to inject malicious web scripts into pages. The core issue arises in the CampaignGridShortcode::parseAttributes() function, where user-supplied attributes such as filter_by, layout, sort_by, and order_by are not properly sanitized. This can lead to a scenario where the json_encode() function outputs data that includes single quotes, potentially breaking out of HTML attributes and executing harmful scripts whenever a user accesses a compromised page.
Affected Version(s)
GiveWP β Donation Plugin and Fundraising Platform 0 <= 4.17.0