CVE-2024-11921: Give < 3.19.0 - Reflected XSS
The GiveWP WordPress plugin before 3.19.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-11921?
CVE-2024-11921 has a medium severity rating due to its potential impact on high privilege users.
How do I fix CVE-2024-11921?
To fix CVE-2024-11921, update the GiveWP WordPress plugin to version 3.19.0 or later.
Who is affected by CVE-2024-11921?
CVE-2024-11921 affects users of the GiveWP WordPress plugin prior to version 3.19.0, particularly high privilege users like administrators.
What type of vulnerability is CVE-2024-11921?
CVE-2024-11921 is classified as a Reflected Cross-Site Scripting (XSS) vulnerability.
Is there a workaround for CVE-2024-11921?
Currently, the best practice for CVE-2024-11921 is to update to the latest version of the GiveWP plugin, as there are no effective workarounds.