Impact
The vulnerability allows an attacker to store malicious script code in the WordPress GiveWP plugin’s data structures. When the site renders the stored data, the scripts execute in visitors’ browsers, potentially enabling session hijacking, credential theft, or defacement. This is a classic Stored XSS flaw that compromises the confidentiality and integrity of the website’s users.
Affected Systems
The flaw affects legacy installations of the Liquid Web / StellarWP GiveWP plugin up to and including version 4.17.0. Any WordPress site deploying these versions is susceptible; newer releases from 4.18.0 onward are safe.
Risk and Exploitability
With a CVSS score of 6.5, the vulnerability presents a moderate risk. The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog, suggesting it has not yet been widely exploited. The attack vector is likely through the plugin’s data submission points, where user‑supplied input is stored without adequate output encoding. Given the stored nature of the payload, an attacker only needs to insert data once to affect all subsequent page views.
OpenCVE Enrichment