CVE-2026-97643: GiveWP <= 4.17.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via givewp_campaign_grid Shortcode Attributes
The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's givewpcampaigngrid shortcode in versions up to, and including, 4.17.0 This is due to insufficient input sanitization and output escaping on user supplied shortcode attributes (filterby, layout, sortby, orderby) in the CampaignGridShortcode::parseAttributes() function combined with the render template emitting jsonencode($attributes) inside a single-quoted HTML attribute without escattr() — jsonencode() does not escape single quotes by default, so a ' in an attribute value breaks out of the enclosing attribute. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
An attacker needs an authenticated WordPress account with Contributor-level permissions or higher. They must be able to place a givewp_campaign_grid shortcode with malicious attribute values into a page or other content that is rendered.
Which shortcode attributes are implicated?
The affected user-supplied attributes are filter_by, layout, sort_by, and order_by. A single quote in one of these values can break out of the single-quoted HTML attribute containing the JSON-encoded shortcode data.
When does the malicious script execute?
The injected script executes when a user accesses the page containing the malicious shortcode. This is stored XSS, so the payload persists in the affected content rather than requiring the attacker to be present when a victim visits.
What can be done if updating is not immediately possible?
Restrict or remove Contributor and higher users' ability to create or edit content containing the givewp_campaign_grid shortcode. Review existing pages and content for that shortcode and for unexpected values in filter_by, layout, sort_by, or order_by.