Impact
The GiveWP plugin for WordPress is vulnerable to a stored cross‑site scripting flaw through the sequoia[introduction][image] form sanitize and escape this input, allowing malicious JavaScript to be a visitor loads the affected form page. The weakness is classified as CWE‑79.
Affected Systems
All installations of the GiveWP plugin from stellarwp that are running any version up to and including 4.16.1 are affected. No information is available about whether versions beyond 4.16.1 contain the fix.
Risk and Exploitability
The CVSS score of 6.4 indicates moderate severity, while an EPSS score of < 1% indicates a very low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires authenticated users with Give Worker+ access; once they inject malicious scripts, those scripts run whenever any visitor accesses the affected form page.
OpenCVE Enrichment