S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2021-25099 Scanner

CVE-2021-25099 scanner - Cross-Site Scripting (XSS) vulnerability in GiveWP plugin for WordPress

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
3.4k
Times Used
continuous scan runs
4.7k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2021-25099
6.1
CVSS

The GiveWP WordPress plugin before 2.17.3 does not sanitise and escape the form_id parameter before outputting it back in the response of an unauthenticated request via the give_checkout_login AJAX action, leading to a Reflected Cross-Site Scripting

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
GiveWP – Donation Plugin and Fundraising Platform
AFFECTED< 2.17.3SAFE ✓≥ 2.17.3
Updated Aug 21, 2026View on NVD →
Detail

GiveWP is a WordPress plugin designed to aid donation campaigns and fundraising efforts. This plugin is commonly used by nonprofit organizations, charities, and political campaigns to easily manage donation collections. The GiveWP plugin provides a user-friendly donation interface, which integrates seamlessly with the WordPress platform. Its features include customizable donation forms, payment gateways, and reports on donations received. However, recent security vulnerabilities have been discovered in the GiveWP plugin, specifically the CVE-2021-25099 vulnerability. 

The CVE-2021-25099 vulnerability is a Reflected Cross-Site Scripting vulnerability found in the GiveWP plugin before version 2.17.3. The vulnerability arises from an unsanitized form_id parameter output in the response of an unauthenticated request via the give_checkout_login AJAX action. As a result, if an attacker attempts to exploit this vulnerability, they can execute arbitrary JavaScript code on the affected website's user's browser. This can lead to sensitive data leakage, user account takeover, and even malware injection.

When the CVE-2021-25099 vulnerability is exploited, attackers can easily access sensitive information from the affected website. Credentials such as login usernames and passwords, as well as other sensitive data such as email addresses, payment information, and personal information can be obtained and used for malicious purposes. This can cause severe reputational damage to the affected organization, loss of trust from donors, and legal repercussions.

Thanks to the pro features of the s4e.io platform, anyone can quickly and easily learn about vulnerabilities in their digital assets. Our advanced security scanning tools identify vulnerabilities in website plugins and themes and provide actionable steps to mitigate the risk of cyber attacks. With 24/7 monitoring and instant alerts, our customers can have peace of mind knowing that their digital assets are secure. Stay ahead of cyber threats and protect your website effectively with s4e.io.

 

REFERENCES

Solution Advice

As a precautionary measure, the following steps can be taken to protect against this vulnerability:

  • Update the GiveWP plugin to its latest version.
  • Use a reputable security plugin that scans for vulnerabilities and malwares.
  • Minimize the use of plugins that have not been updated regularly.
  • Enforce the HTTPS protocol to encrypt all traffic between the website and the user's browser.
  • Use strong and unique passwords, enable two-factor authentication, and limit user privileges.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.