CVE-2021-24315

CVE-2021-24315: Give WP < 2.10.4 - Authenticated Stored Cross-Site Scripting (XSS)

Vendor Givewp
Product GiveWP – Donation Plugin and Fundraising Platform
Weakness CWE-79 · XSS
Published May 17, 2021
Last update August 3, 2024

CVSS base score

What the vulnerability does

01Description

The GiveWP – Donation Plugin and Fundraising Platform WordPress plugin before 2.10.4 did not sanitise or escape the Background Image field of its Stripe Checkout Setting and Logo field in its Email settings, leading to authenticated (admin+) Stored XSS issues.

Key dates

02Disclosure timeline

May 17, 2021 CVE published
August 3, 2024 Record updated