Record summary

CVE-2021-24315 has a selected CVSS score of 4.8 (medium).

Description

The GiveWP – Donation Plugin and Fundraising Platform WordPress plugin before 2.10.4 did not sanitise or escape the Background Image field of its Stripe Checkout Setting and Logo field in its Email settings, leading to authenticated (admin+) Stored XSS issues.

Description source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus

GiveWP – Donation Plugin and Fundraising Platform

Browse GiveWP / GiveWP – Donation Plugin and Fundraising Platform
CVE List2.10.4 to < 2.10.4affected

References

3