CVE-2021-24213: GiveWP < 2.10.0 - Reflected Cross Site Scripting (XSS)
The GiveWP – Donation Plugin and Fundraising Platform WordPress plugin before 2.10.0 was affected by a reflected Cross-Site Scripting vulnerability inside of the administration panel, via the 's' GET parameter on the Donors page.
Other sources
The GiveWP – Donation Plugin and Fundraising Platform WordPress plugin before 2.10.0 was affected by a reflected Cross-Site Scripting vulnerability inside of the administration panel, via the 's' GET parameter on the Donors page.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-24213?
CVE-2021-24213 is a reflected Cross-Site Scripting vulnerability in the GiveWP Donation Plugin and Fundraising Platform WordPress plugin before version 2.10.0.
What software versions are affected by CVE-2021-24213?
The GiveWP GiveWP WordPress plugin versions between 2.4.0 and 2.10.0 are affected by CVE-2021-24213.
How severe is CVE-2021-24213?
CVE-2021-24213 has a severity rating of medium with a CVSS score of 6.1.
How can I fix CVE-2021-24213?
To fix CVE-2021-24213, update the GiveWP Donation Plugin and Fundraising Platform WordPress plugin to version 2.10.0 or higher.
What is the CWE category of CVE-2021-24213?
CVE-2021-24213 falls under CWE category 79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting').