
Reflected XSS in GiveWP <3.19.0 via unsanitized give-clear-update param. Unauth attacker phishes admins for JS exec, session hijack. CVSS 7.1. Patch now. #CVE-2024-11921 #XSS #WordPress #DevSecOps #DevOps #Developers infosec: https://www.valtersit.com/cve/2026/04/cve-2026-4659/
Post summary
The post highlights a reflected XSS vulnerability in GiveWP with a CVSS score of 7.1 and announces that a patch is now available.
