CVE-2026-34900: WordPress GiveWP plugin <= 4.14.2 - Reflected Cross Site Scripting (XSS) vulnerability
Unauthenticated Cross Site Scripting (XSS) in GiveWP <= 4.14.2 versions.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress GiveWP pluginto a version that resolves this vulnerability.Fixed in 4.14.3
Event History
Frequently Asked Questions
What is the severity of CVE-2026-34900?
The severity of CVE-2026-34900 is classified as high with a score of 7.1.
What is CVE-2026-34900?
CVE-2026-34900 is an unauthenticated reflected Cross Site Scripting (XSS) vulnerability in versions of the GiveWP plugin up to 4.14.2.
How do I fix CVE-2026-34900?
To fix CVE-2026-34900, update the GiveWP plugin to a version later than 4.14.2.
What are the potential impacts of CVE-2026-34900?
The potential impacts of CVE-2026-34900 include the possibility for attackers to execute arbitrary scripts in the context of users visiting the affected site.
Who is affected by CVE-2026-34900?
Users of the GiveWP plugin running versions 4.14.2 or earlier are affected by CVE-2026-34900.