Sceawere

Vulnerability Detail

CVE-2026-104672UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Unauthenticated XSS in GiveWP

Vulnerability Metadata

Severity
High
Score / CVSS
7.1
Creation Date
16h ago
Vendor
Nexcess
Product
GiveWP
Attack Type
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
Attack Complexity
LOW

Narrative and Response

Description

Unauthenticated Cross Site Scripting (XSS) in GiveWP <= 4.17.0 versions.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.1",
  "pubDate": "2026-10-06T09:17:39.483Z",
  "pubdate": "2026-10-06T09:17:39.483Z",
  "executiveSummary": "The GiveWP plugin for WordPress, specifically versions 4.17.0 and below, is susceptible to an unauthenticated Cross-Site Scripting (XSS) vulnerability. This security flaw allows remote, unauthenticated attackers to inject malicious JavaScript code into web pages viewed by other users, including site administrators.\nThe vulnerability resides in the improper handling of user-supplied input, which is subsequently rendered in the browser without adequate sanitization or output encoding. Because the attack does not require authentication, it presents a significant risk to the integrity and security of the WordPress installation.\nSuccessful exploitation enables attackers to execute arbitrary scripts within the context of the victim's session. Potential impacts include the theft of sensitive session cookies, unauthorized administrative actions performed on behalf of the victim, redirection to malicious domains, or the defacement of the affected website. Given the popularity of GiveWP for donation management, this vulnerability could be leveraged to manipulate financial transaction flows or compromise donor data by targeting administrative sessions.",
  "technicalDetails": "The vulnerability is classified as an Unauthenticated Stored or Reflected Cross-Site Scripting (XSS) flaw, stemming from the insufficient sanitization of input parameters within the GiveWP plugin. The root cause is the failure of the application to enforce strict output encoding when displaying user-supplied data back to the browser.\nIn the context of GiveWP, this occurs when an attacker crafts a malicious request containing script tags or event handlers within URL parameters or form inputs processed by the plugin. If the application reflects this input directly into the HTML document structure of the generated page without first sanitizing the content or utilizing proper context-aware output escaping, the browser interprets the input as executable code.\nThe attack flow typically initiates when an unauthenticated attacker identifies a vulnerable endpoint or input vector within the GiveWP plugin that does not implement nonce validation or capability checks. The attacker constructs a malicious payload—such as '<script>alert(document.cookie)</script>' or an obfuscated equivalent—and transmits it to the server. Upon the victim navigating to the affected URL or interacting with the compromised component, the server reflects the malicious payload. The victim's browser, trusting the origin of the page, executes the injected JavaScript code.\nBecause the payload executes within the victim's browser session, the attacker can leverage the browser's access to the DOM to perform unauthorized operations. In a post-exploitation scenario, the script can be used to capture administrative session tokens, which could lead to full site takeover if the victim possesses high-level privileges. Furthermore, the payload may modify the site's content, manipulate donation forms to redirect funds, or exfiltrate sensitive data displayed on the dashboard. The vulnerability affects all versions up to 4.17.0, meaning any site utilizing this version without additional web application firewall (WAF) protection is potentially exposed to exploitation via the public internet."
}
CVE-2026-104672: Unauthenticated XSS in GiveWP (HIGH Severity, CVSS: 7.1) | Sceawere