First published: Mon Feb 21 2022(Updated: )
The GiveWP WordPress plugin before 2.17.3 does not escape the s parameter before outputting it back in an attribute in the Donation Forms dashboard, leading to a Reflected Cross-Site Scripting
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
Givenu Givenu Give | <2.17.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-25100 is a vulnerability found in the GiveWP WordPress plugin before version 2.17.3 that allows for Reflected Cross-Site Scripting (XSS) attacks.
CVE-2021-25100 has a severity rating of medium.
The affected software for CVE-2021-25100 is the GiveWP WordPress plugin before version 2.17.3.
The vulnerability can be exploited by an attacker by injecting malicious code into the 's' parameter of the Donation Forms dashboard, leading to a Reflected Cross-Site Scripting (XSS) attack.
To fix CVE-2021-25100, it is recommended to update the GiveWP WordPress plugin to version 2.17.3 or later, which addresses the vulnerability.