First published: Mon Aug 23 2021(Updated: )
The GiveWP – Donation Plugin and Fundraising Platform WordPress plugin before 2.12.0 did not escape the Donation Level setting of its Donation Forms, allowing high privilege users to use Cross-Site Scripting payloads in them.
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
Givenu Givenu Give | <2.12.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-24524 is a vulnerability in the GiveWP – Donation Plugin and Fundraising Platform WordPress plugin before 2.12.0 that allows high privilege users to use Cross-Site Scripting payloads in the Donation Forms.
The severity of CVE-2021-24524 is medium with a severity score of 4.8 out of 10.
CVE-2021-24524 affects the GiveWP – Donation Plugin before version 2.12.0 by not escaping the Donation Level setting of its Donation Forms, allowing high privilege users to use Cross-Site Scripting payloads.
To fix CVE-2021-24524, update the GiveWP – Donation Plugin to version 2.12.0 or later.
You can find more information about CVE-2021-24524 at the following link: [CVE-2021-24524](https://wpscan.com/vulnerability/5a4774ec-c0ee-4c6b-92a6-fa10821ec336).