Vulnerability Description
The GiveWP – Donation Plugin and Fundraising Platform WordPress plugin before 2.10.4 did not sanitise or escape the Background Image field of its Stripe Checkout Setting and Logo field in its Email settings, leading to authenticated (admin+) Stored XSS issues.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Givewp | Givewp | < 2.10.4 |
Related Weaknesses (CWE)
References
- https://m0ze.ru/vulnerability/%5B2021-04-02%5D-%5BWordPress%5D-%5BCWE-79%5D-GiveExploitThird Party Advisory
- https://wpscan.com/vulnerability/006b37c9-641c-4676-a315-9b6053e001d2ExploitThird Party Advisory
- https://m0ze.ru/vulnerability/%5B2021-04-02%5D-%5BWordPress%5D-%5BCWE-79%5D-GiveExploitThird Party Advisory
- https://wpscan.com/vulnerability/006b37c9-641c-4676-a315-9b6053e001d2ExploitThird Party Advisory
FAQ
What is CVE-2021-24315?
CVE-2021-24315 is a vulnerability with a CVSS score of 4.8 (MEDIUM). The GiveWP – Donation Plugin and Fundraising Platform WordPress plugin before 2.10.4 did not sanitise or escape the Background Image field of its Stripe Checkout Setting and Logo field in its Email se...
How severe is CVE-2021-24315?
CVE-2021-24315 has been rated MEDIUM with a CVSS base score of 4.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-24315?
Check the references section above for vendor advisories and patch information. Affected products include: Givewp Givewp.