CVE-2021-25100: Give < 2.17.3 - Reflected Cross-Site Scripting via Donation Forms Dashboard
The GiveWP WordPress plugin before 2.17.3 does not escape the s parameter before outputting it back in an attribute in the Donation Forms dashboard, leading to a Reflected Cross-Site Scripting
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-25100?
CVE-2021-25100 is a vulnerability found in the GiveWP WordPress plugin before version 2.17.3 that allows for Reflected Cross-Site Scripting (XSS) attacks.
What is the severity of CVE-2021-25100?
CVE-2021-25100 has a severity rating of medium.
What is the affected software for CVE-2021-25100?
The affected software for CVE-2021-25100 is the GiveWP WordPress plugin before version 2.17.3.
How can the vulnerability be exploited?
The vulnerability can be exploited by an attacker by injecting malicious code into the 's' parameter of the Donation Forms dashboard, leading to a Reflected Cross-Site Scripting (XSS) attack.
How can CVE-2021-25100 be fixed?
To fix CVE-2021-25100, it is recommended to update the GiveWP WordPress plugin to version 2.17.3 or later, which addresses the vulnerability.