CVE-2026-73357: WordPress GiveWP plugin < 4.16.6 - Cross Site Scripting (XSS) vulnerability
Published Aug 13, 2026
·Updated
Donor Cross Site Scripting (XSS) in GiveWP < 4.16.6 versions.
Affected Software
1 affected component
WordPress GiveWP plugin<4.16.6
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress GiveWP pluginto a version that resolves this vulnerability.Fixed in 4.16.6
Event History
Aug 13, 2026
CVE Published
via MITRE·01:37 PM
Data Sourced
via MITRE·01:37 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-73357?
The severity of CVE-2026-73357 is classified as medium with a score of 6.5.
2
How do I fix CVE-2026-73357?
To fix CVE-2026-73357, update the GiveWP plugin to version 4.16.6 or later.
3
What type of vulnerability is represented by CVE-2026-73357?
CVE-2026-73357 represents a Cross Site Scripting (XSS) vulnerability in the GiveWP plugin.
4
Is CVE-2026-73357 present in all versions of the GiveWP plugin?
CVE-2026-73357 affects versions of the GiveWP plugin prior to 4.16.6.
5
What potential impact does CVE-2026-73357 have on a website?
CVE-2026-73357 can allow attackers to execute malicious scripts in the context of the user's session.