m0ze.ru
https://m0ze.ru/vulnerability/%5B2021-04-02%5D-%5BWordPress%5D-%5BCWE-79%5D-GiveWP-WordPress-Plugin-v2.10.3.txt CVE-2021-24315
MEDIUM
Give WP < 2.10.4 - Authenticated Stored Cross-Site Scripting (XSS)
Record summary
CVE-2021-24315 has a selected CVSS score of 4.8 (medium).
Description
The GiveWP – Donation Plugin and Fundraising Platform WordPress plugin before 2.10.4 did not sanitise or escape the Background Image field of its Stripe Checkout Setting and Logo field in its Email settings, leading to authenticated (admin+) Stored XSS issues.
Description source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
GiveWP – Donation Plugin and Fundraising PlatformBrowse GiveWP / GiveWP – Donation Plugin and Fundraising Platform | CVE List | 2.10.4 to < 2.10.4 | affected |
References
3nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2021-24315 wpscan.comConfirmation
https://wpscan.com/vulnerability/006b37c9-641c-4676-a315-9b6053e001d2