CVE-2026-104672: WordPress GiveWP plugin <= 4.17.0 - Cross Site Scripting (XSS) vulnerability
Unauthenticated Cross Site Scripting (XSS) in GiveWP <= 4.17.0 versions.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress GiveWP pluginto a version that resolves this vulnerability.Fixed in 4.18.0
Event History
Frequently Asked Questions
What does an attacker need to exploit this issue?
The vulnerability is unauthenticated, so the attacker does not need an account or other privileges. Exploitation requires user interaction, as reflected by the UI:R attack-vector metric.
Which installations are affected?
GiveWP versions 4.17.0 and earlier are identified as affected. The provided information does not state whether any particular WordPress or GiveWP configuration prevents exploitation.
What impact could successful exploitation have?
The supplied severity vector indicates low impact to confidentiality, integrity, and availability, with scope changed. The issue is classified as cross-site scripting (XSS).