Loading
The GiveWP WordPress plugin before 2.24.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks
Use Givewp vendor hub and Givewp product page to widen CVE-2022-4448 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2025-0912, CVE-2025-22777 and CVE-2024-12877 for nearby disclosures in the same product family.