CVE-2026-14318

The GiveWP WordPress plugin before 4.16.3 does not escape a donation-form template setting before outputting it in an HTML attribute, allowing users with the GiveWP Worker role and above to inject arbitrary web scripts that execute on the public donation form viewed by any visitor.
Configurations

No configuration.

History

No history.

Information

Published : 2026-07-30 06:25

Updated : 2026-07-30 16:45


NVD link : CVE-2026-14318

Mitre link : CVE-2026-14318

CVE.ORG link : CVE-2026-14318


JSON object : View

Products Affected

No product.

CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')