← All CVEs NewScan detects
medium

CVE-2026-85113

GiveWP stored shortcode injection - donor-supplied values are rendered on public pages with shortcode delimiters intact

Severity
medium
Affected product
give
Affected versions
give < 4.16.9
Fixed in
give 4.16.9
Added to NewScan
2026-09-21
Detected by
NewScan — free, self-hosted

How NewScan reports it

COMPONENT VERSION RANGE

NewScan fingerprints give from its response and reports this CVE when the detected version falls inside the affected range below.

Added 2026-09-21. Directory slug `give` (plugin title 'GiveWP - Donation Plugin and Fundraising Platform'), confirmed against api.wordpress.org, whose current release is exactly the 4.16.9 fix. GiveWP does not strip shortcode delimiters from donor-supplied values before rendering them on public donor/donation pages, and the stripping it does apply is incomplete - so a donor controls shortcode execution in the context of any page that renders their record. No `ge`: every release before 4.16.9 is affected and GiveWP's 1.x-4.x line is one continuous series, so a lower bound would only create a silent gap. Version source is the standard component route - GiveWP enqueues /wp-content/plugins/give/assets/...?ver=<plugin version> on any page carrying a donation form, refined by the readme.txt `Stable tag:` probe. Version-match only: reproducing it would mean writing attacker-controlled content into the customer's donor records.

References

Scan for this yourself — local, in-band scanning is free.

Get NewScan (FREE) →