CVE-2019-15317: XSS
Published Aug 22, 2019
·Updated
The give plugin before 2.4.7 for WordPress has XSS via a donor name.
Affected Software
1 affected component
GiveWP GiveWP WordPress<2.4.7
Event History
Aug 22, 2019
CVE Published
via MITRE·12:21 PM
Data Sourced
via MITRE·12:21 PM
Description
Frequently Asked Questions
1
What is CVE-2019-15317?
CVE-2019-15317 is a vulnerability in the Give plugin for WordPress that allows for cross-site scripting (XSS) attacks via a donor name.
2
What is the severity of CVE-2019-15317?
The severity of CVE-2019-15317 is medium with a score of 5.4.
3
How does CVE-2019-15317 affect WordPress?
CVE-2019-15317 affects WordPress installations that have the Give plugin version up to 2.4.7.
4
What is cross-site scripting (XSS)?
Cross-site scripting (XSS) is a type of security vulnerability that allows attackers to inject malicious scripts into web pages viewed by other users.
5
How can I fix the CVE-2019-15317 vulnerability?
To fix the CVE-2019-15317 vulnerability, update the Give plugin to version 2.4.7 or higher.