What is CVE-2026-14318?
CVE-2026-14318 is a Stored XSS vulnerability in the GiveWP WordPress plugin where a donation-form template setting is not properly escaped before being output in an HTML attribute. This allows users with the GiveWP Worker role or higher to inject arbitrary web scripts that execute on the public donation form viewed by any visitor. Updating the plugin to version 4.16.3 or later mitigates the risk.
Azərbaycanca: CVE-2026-14318, GiveWP WordPress plaginində HTML atributunda istifadə edilməzdən əvvəl donation-form şablon parametrinin escape olunmaması ilə bağlı Stored XSS zəifliyidir. Bu, GiveWP Worker rolu və yuxarısına malik istifadəçilərə arbitrari skriptlər inyeksiya etməyə imkan verir ki, bu skriptlər ziyarətçilərin ictimai donation formasında icra olunur. Plagini ən azı 4.16.3 versiyasına yeniləmək təsirlənmənin qarşısını alır.
Related CVEs
link basis: same weakness class CWE-79
FAQ2
What user permission level is required to exploit this vulnerability?
This Stored XSS vulnerability can be exploited by users with the GiveWP Worker role or higher.
Updating the affected WordPress plugin to which version mitigates the risk?
Updating the GiveWP plugin to version 4.16.3 or later mitigates the risk from this vulnerability.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.