Vulnerabilities > Givewp > Givewp > 2.10.2

DATE CVE VULNERABILITY TITLE RISK
2022-02-21 CVE-2022-0252 Unspecified vulnerability in Givewp
The GiveWP WordPress plugin before 2.17.3 does not escape the json parameter before outputting it back in an attribute in the Import admin dashboard, leading to a Reflected Cross-Site Scripting
network
low complexity
givewp
6.1
2021-08-23 CVE-2021-24524 Unspecified vulnerability in Givewp
The GiveWP – Donation Plugin and Fundraising Platform WordPress plugin before 2.12.0 did not escape the Donation Level setting of its Donation Forms, allowing high privilege users to use Cross-Site Scripting payloads in them.
network
low complexity
givewp
4.8
2021-05-17 CVE-2021-24315 Unspecified vulnerability in Givewp
The GiveWP – Donation Plugin and Fundraising Platform WordPress plugin before 2.10.4 did not sanitise or escape the Background Image field of its Stripe Checkout Setting and Logo field in its Email settings, leading to authenticated (admin+) Stored XSS issues.
network
low complexity
givewp
4.8