cleantalk

Vulnerabilities and Security Researches

Security report for CVE GiveWP – Donation Plugin and Fundraising Platform > CVE-2021-24315

CVE, Research URL

CVE-2021-24315

Published on
May 17, 2021
Research Description
The GiveWP – Donation Plugin and Fundraising Platform WordPress plugin before 2.10.4 did not sanitise or escape the Background Image field of its Stripe Checkout Setting and Logo field in its Email settings, leading to authenticated (admin+) Stored XSS issues.
Affected versions
Min -, max 2.10.4.
Status
vulnerable