CVE-2024-11921

MEDIUM NUCLEI

GiveWP <3.19.0 - XSS

Title source: llm

Description

The GiveWP WordPress plugin before 3.19.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

Nuclei Templates (1)

Give WP Plugin < 3.19.0 - Cross-Site Scripting
HIGHby Splint3r7

Scores

CVSS v3 4.8
EPSS 0.0200
EPSS Percentile 83.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N

Details

CWE
CWE-79
Status published
Products (1)
givewp/givewp < 3.19.0
Published Dec 27, 2024
Tracked Since Feb 18, 2026