First published: Thu Aug 22 2019(Updated: )
The give plugin before 2.4.7 for WordPress has XSS via a donor name.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Givenu Givenu Give | <2.4.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-15317 is a vulnerability in the Give plugin for WordPress that allows for cross-site scripting (XSS) attacks via a donor name.
The severity of CVE-2019-15317 is medium with a score of 5.4.
CVE-2019-15317 affects WordPress installations that have the Give plugin version up to 2.4.7.
Cross-site scripting (XSS) is a type of security vulnerability that allows attackers to inject malicious scripts into web pages viewed by other users.
To fix the CVE-2019-15317 vulnerability, update the Give plugin to version 2.4.7 or higher.