CVE-2021-24315

Severity CVSS v4.0:
Pending analysis
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
17/05/2021
Last modified:
07/11/2023

Description

The GiveWP – Donation Plugin and Fundraising Platform WordPress plugin before 2.10.4 did not sanitise or escape the Background Image field of its Stripe Checkout Setting and Logo field in its Email settings, leading to authenticated (admin+) Stored XSS issues.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:givewp:givewp:*:*:*:*:*:wordpress:*:* 2.10.4 (excluding)