Impact
The vulnerability occurs in the GiveWP WordPress plugin before version 4.16.6 and allows an attacker to inject malicious scripts through the donor interface. Affected users who view the compromised page would run the injected code in their browser, potentially stealing session cookies, defacing content, or conducting phishing attacks. The weakness is a classic input validation flaw described by CWE‑79.
Affected Systems
Users of the Nexcess:GiveWP plugin on WordPress installations whose plugin version is older than 4.16.6 are susceptible. No specific sub‑versions are listed, so all releases below 4.16.6 may be affected.
Risk and Exploitability
The CVSS score of 6.5 marks this as a medium‑severity issue, and the EPSS score is currently unavailable. It is not listed in the CISA KEV catalog. Based on the description, it is inferred that the likely attack vector is remote via a browser interaction with the vulnerable donor page; any authenticated or unauthenticated user who visits the page could be impacted. The impact is confined to the victim's browser, making it a client‑side compromise with potential data theft or defacement.
OpenCVE Enrichment