CVE-2026-14318

The GiveWP WordPress plugin before 4.16.3 does not escape a donation-form template setting before outputting it in an HTML attribute, allowing users with the GiveWP Worker role and above to inject arbitrary web scripts that execute on the public donation form viewed by any visitor.
Configurations

No configuration.

History

30 Jul 2026, 15:16

Type Values Removed Values Added
CWE CWE-79
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.8

30 Jul 2026, 06:25

Type Values Removed Values Added
New CVE

Information

Published : 2026-07-30 06:25

Updated : 2026-07-30 16:45


NVD link : CVE-2026-14318

Mitre link : CVE-2026-14318

CVE.ORG link : CVE-2026-14318


JSON object : View

Products Affected

No product.

CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')