Project Subscriptions
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Mon, 21 Sep 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-74 | |
| Metrics |
ssvc
|
Mon, 21 Sep 2026 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Givewp
Givewp givewp Wordpress Wordpress wordpress |
|
| Vendors & Products |
Givewp
Givewp givewp Wordpress Wordpress wordpress |
Mon, 21 Sep 2026 09:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The GiveWP WordPress plugin before 4.16.9 does not remove shortcode delimiters from donor-supplied values before rendering them on public pages, and the shortcode stripping it applies can be defeated by nesting, allowing unauthenticated users to execute arbitrary shortcodes registered on the site. | |
| Title | GiveWP < 4.16.9 - Unauthenticated Arbitrary Shortcode Execution via Donor Name | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2026-09-21T14:30:21.144Z
Reserved: 2026-09-03T07:44:04.337Z
Link: CVE-2026-85113
Updated: 2026-09-21T14:30:08.175Z
Status : Deferred
Published: 2026-09-21T09:17:06.040
Modified: 2026-09-21T15:17:32.737
Link: CVE-2026-85113
No data.
OpenCVE Enrichment
Updated: 2026-09-21T18:15:16Z