CVE-2021-24524
23.08.2021, 12:15
The GiveWP Donation Plugin and Fundraising Platform WordPress plugin before 2.12.0 did not escape the Donation Level setting of its Donation Forms, allowing high privilege users to use Cross-Site Scripting payloads in them.
Vendor | Product | Version |
---|---|---|
givewp | givewp | 𝑥 < 2.12.0 |
𝑥
= Vulnerable software versions