CVE-2026-14318

MEDIUM

GiveWP < 4.16.3 - GiveWP Worker+ Stored XSS via Donation Form Template Settings

Title source: cna
STIX 2.1

Description

The GiveWP WordPress plugin before 4.16.3 does not escape a donation-form template setting before outputting it in an HTML attribute, allowing users with the GiveWP Worker role and above to inject arbitrary web scripts that execute on the public donation form viewed by any visitor.

References (1)

Core 1
Core References
Exploit exploit vdb-entry technical-description
https://wpscan.com/vulnerability/2957014f-542d-43fc-ad65-de236446eeeb/

Scores

CVSS v3 6.8
EPSS 0.0017
EPSS Percentile 6.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-79
Status published
Products (1)
None/GiveWP < 4.16.3
Published Jul 30, 2026
Tracked Since Jul 30, 2026