CVE-2026-96830: WordPress GiveWP plugin <= 4.16.9 - Cross Site Scripting (XSS) vulnerability
Unauthenticated Cross Site Scripting (XSS) in GiveWP <= 4.16.9 versions.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress GiveWP pluginto a version that resolves this vulnerability.Fixed in 4.17.0
Event History
Frequently Asked Questions
Who can exploit this issue?
The vulnerability is unauthenticated, so an attacker does not need a WordPress account or GiveWP privileges. Exploitation does require user interaction, as reflected by the UI:R vector.
What installations are affected?
GiveWP versions up to and including 4.16.9 are identified as affected. The available data does not state whether a particular GiveWP configuration or feature must be enabled.
What is the potential impact if exploitation succeeds?
The vulnerability can result in limited confidentiality, integrity, and availability impact, and its scope may extend beyond the vulnerable component. As an XSS issue, it involves attacker-supplied script executing in a user's browser after interaction.