Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Liquid Web / StellarWP GiveWP give allows Stored XSS.This issue affects GiveWP: from n/a through 4.17.0.
Published: 2026-10-05
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Stored Cross‑Site Scripting
Action: Immediate Patch
AI Analysis

Impact

The vulnerability allows an attacker to store malicious script code in the WordPress GiveWP plugin’s data structures. When the site renders the stored data, the scripts execute in visitors’ browsers, potentially enabling session hijacking, credential theft, or defacement. This is a classic Stored XSS flaw that compromises the confidentiality and integrity of the website’s users.

Affected Systems

The flaw affects legacy installations of the Liquid Web / StellarWP GiveWP plugin up to and including version 4.17.0. Any WordPress site deploying these versions is susceptible; newer releases from 4.18.0 onward are safe.

Risk and Exploitability

With a CVSS score of 6.5, the vulnerability presents a moderate risk. The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog, suggesting it has not yet been widely exploited. The attack vector is likely through the plugin’s data submission points, where user‑supplied input is stored without adequate output encoding. Given the stored nature of the payload, an attacker only needs to insert data once to affect all subsequent page views.

Generated by OpenCVE AI on October 5, 2026 at 10:45 UTC.

Remediation

Vendor Solution

Update the WordPress GiveWP plugin to the latest available version (at least 4.18.0).


OpenCVE Recommended Actions

  • Upgrade the GiveWP plugin to version 4.18.0 or newer.
  • If an upgrade is impossible, disable the plugin or remove any custom fields that allow user input from GiveWP.
  • Deploy a Content Security Policy that blocks inline scripts and restricts script sources to trusted origins.
  • Ensure all plugins, themes, and core WordPress components are kept current to reduce the attack surface.

Generated by OpenCVE AI on October 5, 2026 at 10:45 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 05 Oct 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 05 Oct 2026 09:00:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Liquid Web / StellarWP GiveWP give allows Stored XSS.This issue affects GiveWP: from n/a through 4.17.0.
Title WordPress GiveWP plugin <= 4.17.0 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-10-05T13:03:22.921Z

Reserved: 2026-10-02T00:22:13.105Z

Link: CVE-2026-104404

cve-icon Vulnrichment

Updated: 2026-10-05T12:56:26.748Z

cve-icon NVD

Status : Received

Published: 2026-10-05T09:17:08.340

Modified: 2026-10-05T14:17:15.940

Link: CVE-2026-104404

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-05T10:45:21Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')