Impact
The GiveWP donation plugin for WordPress is vulnerable to Stored Cross‑Site Scripting via the 'twitter_message' setting in the Sequoia donation confirmation template in all releases up to 4.16.3; insufficient input sanitization and output escaping allows an authenticated attacker with give worker‑level access or higher to store arbitrary JavaScript that will execute in a donor's browser when the share on Twitter button is clicked, providing a stored XSS vector.
Affected Systems
The vulnerability affects all versions of the GiveWP plugin released by StellarWP, from the initial release through version 4.16.3.
Risk and Exploitability
With a CVSS score of 6.4, the flaw is rated medium severity; the EPSS score is below 1% and the issue is not listed in the CISA KEV catalog. Exploitation requires an attacker to have give worker or higher privileges, a role typically granted to site editors or administrators, after which the stored payload is automatically executed on any donor’s browser that clicks the Share button. While the likelihood is low, the attack can affect multiple donors if the compromised setting is used on a shared or public donation page.
OpenCVE Enrichment