CVE Published: 17/05/2021 |
CVE Updated: 03/08/2024 |
CVE Year: 2021 Source: WPScan |
Vendor: GiveWP |
Product: GiveWP – Donation Plugin and Fundraising Platform Status : PUBLISHED
CVE-2021-24315 Description
The GiveWP – Donation Plugin and Fundraising Platform WordPress plugin before 2.10.4 did not sanitise or escape the Background Image field of its Stripe Checkout Setting and Logo field in its Email settings, leading to authenticated (admin+) Stored XSS issues.