CVE-2026-14318
MEDIUMGiveWP < 4.16.3 - GiveWP Worker+ Stored XSS via Donation Form Template Settings
Title source: cnaDescription
The GiveWP WordPress plugin before 4.16.3 does not escape a donation-form template setting before outputting it in an HTML attribute, allowing users with the GiveWP Worker role and above to inject arbitrary web scripts that execute on the public donation form viewed by any visitor.
References (1)
Core 1
Core References
Exploit exploit
vdb-entry
technical-description
https://wpscan.com/vulnerability/2957014f-542d-43fc-ad65-de236446eeeb/
Scores
CVSS v3
6.8
EPSS
0.0017
EPSS Percentile
6.8%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
total
Details
CWE
CWE-79
Status
published
Products (1)
None/GiveWP
< 4.16.3
Published
Jul 30, 2026
Tracked Since
Jul 30, 2026