CVE-2024-11921: medium-severity vulnerability in GiveWP
Give < 3.19.0 - Reflected XSS
Published
28Vexday Risk Score
Patch soon. It has a working public exploit.
ssvc Attendcvss 4.8epss 0.8%
exploitation probability
0.8%top 45% of all CVEs
observed exploitation
nono source reports it
The GiveWP WordPress plugin before 3.19.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Affected products
Unknown · GiveWPRelated CVEs — GiveWP
In the same product, most dangerous first.
CVE-2023-0224CRITICALGiveWP < 2.24.1 - Unauthenticated SQLiEPSS 3.7%CVE-2022-4448MEDIUMGiveWP < 2.24.0 - Contributor+ Stored XSSEPSS 0.6%CVE-2026-14319HIGHGiveWP < 4.16.3 - Unauthenticated Recurring Donor Information DisclosureEPSS 0.4%CVE-2026-14318MEDIUMGiveWP < 4.16.3 - GiveWP Worker+ Stored XSS via Donation Form Template SettingsEPSS 0.4%CVE-2026-85530HIGHGiveWP < 4.16.8.1 - Unauthenticated Account Takeover via Donor Email Sanitization MismatchEPSS 0.4%CVE-2026-85113MEDIUMGiveWP < 4.16.9 - Unauthenticated Arbitrary Shortcode Execution via Donor NameEPSS 0.3%