S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Jan 6, 2025

CVE-2024-11921 Scanner

CVE-2024-11921 Scanner - Cross-Site Scripting vulnerability in Give WP Plugin

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.8k
Times Used
continuous scan runs
4.8k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2024-11921
4.8
CVSSmedium
Exploitable remotely over the internet · requires high privileges · user interaction needed.

The GiveWP WordPress plugin before 3.19.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

Attack Vector
Network
Privileges Req.
High
User Interaction
Required
Affected
GiveWP
AFFECTED< 3.19.0SAFE ✓≥ 3.19.0
Updated Aug 22, 2026View on NVD →
Detail

Give WP Plugin is a WordPress donation plugin widely used by non-profits, charities, and individuals to manage fundraising campaigns. It provides features for accepting online donations, tracking contributors, and integrating with multiple payment gateways. The plugin is a popular choice for building professional fundraising platforms.

Cross-Site Scripting (XSS) is a vulnerability that allows attackers to inject malicious scripts into web pages viewed by users. This can lead to session hijacking, data theft, or unauthorized actions within the affected application. In this case, the vulnerability is caused by improper sanitization and escaping of user input.

The vulnerability in the Give WP Plugin exists in a parameter used in the administration pages. Unsanitized and improperly escaped input allows attackers to insert malicious scripts that execute in the context of the affected user, particularly administrators. The issue affects versions below 3.19.0.

If exploited, this vulnerability can enable attackers to perform unauthorized actions, steal sensitive information, or compromise administrator accounts. Malicious actors could also leverage the flaw to alter the configuration or content of the fundraising platform.

REFERENCES

Solution Advice
  • Update to Give WP Plugin version 3.19.0 or later to patch the vulnerability.
  • Ensure proper sanitization and escaping of all user input, especially parameters used in admin pages.
  • Limit access to administrative functions to trusted users and monitor activity logs for suspicious behavior.
  • Implement Content Security Policy (CSP) headers to prevent execution of unauthorized scripts.
  • Conduct regular security audits and vulnerability assessments to identify and address risks.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.