Skip to content
Wordpress Givewp Plugin 4 16 9 Cross Site Scripting Xss Vulnerability

Wordpress Givewp Plugin 4 16 9 Cross Site Scripting Xss Vulnerability

patchstack.com • September 30, 2026

As immediate action, update the affected plugin. If you're unable to do so, ask your hosting provider or web developer for help.

User Interaction Required

While this vulnerability can be initiated by the role shown in "Required Privilege", successful exploitation requires a privileged user to perform an action — such as clicking a malicious link, visiting a crafted page, or submitting a form.

Cross Site Scripting (XSS)

Attackers can inject malicious scripts into the site that steal visitor data or hijack their accounts.

CVSS score is a way to evaluate and rank reported vulnerabilities in a standardized and repeatable way but which is not ideal for WordPress.

We advise to mitigate or resolve the vulnerability immediately.

Automatically mitigate vulnerabilities and keep your websites safe.

Patchstack has issued a mitigation rule to block any attacks until you have updated to a patched version.

Update to version 4.17.0 or later.

Update to version 4.17.0 or later to resolve the vulnerability. Patchstack users can turn on auto-update for vulnerable plugins only.

Extracted Entities

Platforms (1)

Vulnerabilities (1)