Impact
The vulnerability allows an attacker to inject malicious client‑side scripts into the WordPress GiveWP plugin without authentication. This can enable session hijacking, theft of credentials, defacement, or malicious redirection within the victim’s browser. The weakness originates from inadequate input validation and escaping, as indicated by CWE‑79.
Affected Systems
The affected product is the GiveWP plugin for WordPress released by Nexcess. Versions up to and including 4.16.5 are vulnerable, while patch version 4.16.5.1 and later contain the fix.
Risk and Exploitability
The CVSS score of 7.1 indicates moderate severity. EPSS data is unavailable, and the vulnerability is not listed in the CISA KEV catalog, suggesting no known public exploits at this time. The likely attack vector is a web‑based input or URL that the plugin does not properly sanitize, allowing an unauthenticated attacker to deliver and execute JavaScript in a victim’s browser.
OpenCVE Enrichment