CVE-2026-13704: GiveWP <= 4.16.1 - Authenticated (Give Worker+) Stored Cross-Site Scripting via Sequioa Form
The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'sequoia[introduction][image]' parameter in all versions up to, and including, 4.16.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Give Worker-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
wordpress/givewpto a version that resolves this vulnerability.Fixed in 4.16.1 - Compensating control
Mitigate Stored XSS risk by restricting access to the Give Worker+ functionality so only trusted authenticated users can access/submit Sequoia form fields such as 'sequoia[introduction][image]'.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-13704?
The severity of CVE-2026-13704 is medium with a score of 6.4.
How do I fix CVE-2026-13704?
To fix CVE-2026-13704, update the GiveWP plugin to the latest version beyond 4.16.1.
What type of vulnerability is CVE-2026-13704?
CVE-2026-13704 is a Stored Cross-Site Scripting (XSS) vulnerability.
Which versions of GiveWP are affected by CVE-2026-13704?
CVE-2026-13704 affects all versions of GiveWP up to and including 4.16.1.
What is the impact of CVE-2026-13704?
The impact of CVE-2026-13704 includes the potential for attackers to inject malicious scripts that can execute in the context of a user’s session.