CVE-2026-104404Medium· 6.5▾ SunlitImproper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Liquid Web / StellarWP GiveWP give allows Stored XSS.This issue affects GiveWP: from n/a through 4.17.0.
▾ Sunlit zone — Low / medium · no exploitation signal
impact 35.8 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Liquid Web / StellarWP GiveWP give allows Stored XSS.This issue affects GiveWP: from n/a through 4.17.0.
give <= 4.17.0Update the WordPress GiveWP plugin to the latest available version (at least 4.18.0).
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-96830High· 7.1Unauthenticated Cross Site Scripting (XSS) in GiveWP <= 4.16.9 versions.
CVE-2026-103354High· 7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Liquid Web / StellarWP Gutenberg Blocks by Kadence Blocks kadence-blocks allows Stored XSS.This issue affects Gutenberg Blocks by Kaden…
CVE-2026-96834Medium· 6.5Subscriber Sensitive Data Exposure in GiveWP <= 4.16.9 versions.
CVE-2026-97066Medium· 5.3Unauthenticated Insecure Direct Object References (IDOR) in GiveWP <= 4.16.9 versions.
CVE-2026-97196Critical· 9.1Improper Validation of Unsafe Equivalence in Input vulnerability in Liquid Web / StellarWP GiveWP allows Authentication Bypass. This issue affects GiveWP: from n/a through 4.16.9.
CVE-2026-104675Medium· 4.3WordPress Event Tickets plugin <= 5.30.0 - Broken Access Control vulnerability