Impact
The vulnerability is a CWE‑79 cross‑site scripting flaw in the WordPress GiveWP plugin versions up to 4.16.3. It allows an unauthenticated attacker to inject arbitrary JavaScript into pages that display plugin output, enabling the execution of malicious code within users' browsers.
Affected Systems
WordPress sites running the GiveWP plugin version 4.16.3 or earlier, as distributed by Nexcess under the GiveWP product line. No other vendors or product versions are listed as affected.
Risk and Exploitability
The CVSS score of 7.1 indicates a medium‑severity risk, and an EPSS score of 0.00146 indicates a very low exploitation probability, with the vulnerability not listed in the CISA KEV catalog. Attackers can exploit this flaw without authentication; the likely attack vector involves submitting crafted input or using a URL that contains malicious payloads which are rendered by the plugin. The lack of an authentication requirement suggests that any visitor to the affected site could trigger the XSS payload.
OpenCVE Enrichment