Impact
The GiveWP donation plugin is vulnerable to stored cross‑site scripting through the block_id and other shortcode attributes of the givewp_campaign_comments shortcode. The vulnerability results from insufficient input sanitization and output escaping, allowing an authenticated author‑level attacker to inject arbitrary JavaScript that executes whenever any user views a page containing the injected shortcode. This is a classic input validation flaw rated CWE‑79.
Affected Systems
All installations of the GiveWP – Donation Plugin and Fundraising Platform plugin from StellarWP with version 4.16.0 or earlier are affected. Sites running WordPress that have this plugin installed and use the givewp_campaign_comments shortcode are at risk.
Risk and Exploitability
The CVSS score of 6.4 indicates a medium severity impact, and the EPSS score is not available. The vulnerability is not listed in CISA’s KEV catalog. Exploitation requires the attacker to have author or higher level access to the site and the ability to add or edit content that includes the vulnerable shortcode. Once an attacker injects malicious script, all visitors to the affected page are exposed to script execution, compromising confidentiality, integrity, and availability of the site’s content.
OpenCVE Enrichment