Sceawere

Vulnerability Detail

CVE-2026-104404UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Stored XSS in GiveWP Plugin

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.5
Creation Date
10h ago
Vendor
Liquid Web / StellarWP
Product
GiveWP
Attack Type
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L
Attack Complexity
LOW

Narrative and Response

Description

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Liquid Web / StellarWP GiveWP give allows Stored XSS.This issue affects GiveWP: from n/a through 4.17.0.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.5",
  "pubDate": "2026-10-05T09:17:08.340Z",
  "pubdate": "2026-10-05T09:17:08.340Z",
  "executiveSummary": "A Stored Cross-Site Scripting (XSS) vulnerability exists in the GiveWP donation plugin for WordPress, developed by StellarWP/Liquid Web. This flaw is classified under CWE-79: Improper Neutralization of Input During Web Page Generation.\nThe vulnerability allows an unauthenticated or authenticated attacker to inject malicious JavaScript payloads into the application's database. When a victim, typically an administrator or a user with elevated privileges, views the affected page where the input is rendered, the malicious script executes within the context of the user's browser session.\nThe impact of this vulnerability is significant, as it can lead to full account takeover, unauthorized administrative actions, redirection to malicious domains, or the exfiltration of sensitive session cookies and data. The vulnerability affects all versions of the GiveWP plugin from the initial release through 4.17.0. Because the malicious content is stored persistently, the attack remains active until the input is sanitized or deleted by administrative intervention. No specific sophisticated exploit requirements are documented beyond the ability to submit input that is subsequently rendered without appropriate output encoding or sanitization in the administrative dashboard or front-end interface.",
  "technicalDetails": "The root cause of this vulnerability is the failure of the GiveWP plugin to adequately sanitize user-supplied input or encode data upon output within the affected components. This constitutes a classic Stored XSS vector, where the application stores untrusted data in the database and reflects it back to the client side without proper character escaping or contextual sanitization.\nThe attack flow begins with the adversary identifying an input field or parameter processed by the GiveWP plugin. The attacker submits a crafted payload containing malicious JavaScript—such as <script>alert(document.cookie)</script> or more complex obfuscated payloads—via the application's submission forms or API endpoints. The application accepts this input and persists it directly into the database.\nWhen a legitimate user, such as a site administrator viewing donation logs or reporting interfaces provided by the GiveWP plugin, navigates to the compromised section, the application retrieves the stored, malicious data and injects it directly into the HTML document object model (DOM) of the browser.\nBecause the payload is rendered as executable code rather than plain text, the victim's browser executes the script automatically. The execution occurs within the security origin of the WordPress site, granting the script access to the document object, including sensitive cookies, session tokens, and the ability to perform actions on behalf of the victim through authenticated requests. If the victim has high-level permissions, the attacker can leverage the XSS to modify site settings, create new administrative users, or inject further malicious content into the site to achieve persistence.\nThe affected component involves the processing logic within GiveWP that handles user-generated data. Since the vulnerability is confirmed in versions up to 4.17.0, it suggests a systemic issue with input handling across multiple modules rather than an isolated function. Exploitation does not necessarily require deep system-level access, depending on where the vulnerable input is processed and displayed; however, the impact is maximized when the vulnerable interface is frequently accessed by privileged users. There is no evidence of automatic sanitization filters in place for the vulnerable input fields, allowing standard XSS vectors to bypass existing controls entirely."
}
CVE-2026-104404: Stored XSS in GiveWP Plugin (MEDIUM Severity, CVSS: 6.5) | Sceawere