Skip to content
CVE / MITRECVE Recent··1 min read

CVE-2026-14987 - GiveWP <= 4.16.3 - Authenticated (Give Worker+) Stored Cross-Site Scripting via 'twitter_message' Sequoia Template Setting

CVE ID :CVE-2026-14987 Published : July 16, 2026, 4:17 a. m. | 38 minutes ago Description :The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'twitter_message' Sequoia Template Setting in all versions up to, and including, 4.

16. 3 due to insufficient input sanitization and output escaping.

Originally reported by CVE Recent
0 comments

0 comments

Posting as BoldLynx589
0/1000

No comments yet. Be the first to start the discussion.