CVE-2021-24524: GiveWP < 2.12.0 - Authenticated Stored XSS
The GiveWP – Donation Plugin and Fundraising Platform WordPress plugin before 2.12.0 did not escape the Donation Level setting of its Donation Forms, allowing high privilege users to use Cross-Site Scripting payloads in them.
Other sources
The GiveWP – Donation Plugin and Fundraising Platform WordPress plugin before 2.12.0 did not escape the Donation Level setting of its Donation Forms, allowing high privilege users to use Cross-Site Scripting payloads in them.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-24524?
CVE-2021-24524 is a vulnerability in the GiveWP – Donation Plugin and Fundraising Platform WordPress plugin before 2.12.0 that allows high privilege users to use Cross-Site Scripting payloads in the Donation Forms.
What is the severity of CVE-2021-24524?
The severity of CVE-2021-24524 is medium with a severity score of 4.8 out of 10.
How does CVE-2021-24524 affect the GiveWP – Donation Plugin?
CVE-2021-24524 affects the GiveWP – Donation Plugin before version 2.12.0 by not escaping the Donation Level setting of its Donation Forms, allowing high privilege users to use Cross-Site Scripting payloads.
How can I fix CVE-2021-24524?
To fix CVE-2021-24524, update the GiveWP – Donation Plugin to version 2.12.0 or later.
Where can I find more information about CVE-2021-24524?
You can find more information about CVE-2021-24524 at the following link: [CVE-2021-24524](https://wpscan.com/vulnerability/5a4774ec-c0ee-4c6b-92a6-fa10821ec336).