Impact
The GiveWP plugin for WordPress is affected by an Improper Neutralization of Input During Web Page Generation flaw that allows DOM Based XSS. The likely impact is that attacker-supplied input can be interpreted as JavaScript and executed in a visitor’s browser, potentially allowing the attacker to run arbitrary client‑side code with the user’s privileges.
Affected Systems
Liquid Web and StellarWP product GiveWP is impacted for all WordPress plugin releases up to version 4.14.5 inclusive. Any deployment of GiveWP from the earliest available build through 4.14.5 is vulnerable.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity. EPSS data is not available, and the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is a crafted URL or link that incorporates unsanitized input, which when processed by the victim’s browser triggers execution of malicious JavaScript. Because the flaw is client-side, it does not require privileged server access, but it does require that an attacker supply the malicious input and that a vulnerable user visits the affected page.
OpenCVE Enrichment