cbcvebase.

Liquid Web Stellarwp Givewp vulnerabilities

6 known vulnerabilities affecting liquid_web/stellarwp_givewp.

Total CVEs
6
CISA KEV
0
Public exploits
1
Exploited in wild
1
Severity breakdown
CRITICAL2HIGH2MEDIUM2

Vulnerabilities

Page 1 of 1
CVE-2026-82222P1CRITICALCVSS 10.0ExploitedPoC≥ n/a, ≤ 4.16.7.12026-08-28
CVE-2026-82222 [CRITICAL] CWE-502 CVE-2026-82222: Deserialization of Untrusted Data vulnerability in Liquid Web / StellarWP GiveWP allows Object Injec Deserialization of Untrusted Data vulnerability in Liquid Web / StellarWP GiveWP allows Object Injection. This issue affects GiveWP: from n/a through 4.16.7.1.
nvd
CVE-2026-97196P2CRITICALCVSS 9.1≥ n/a, ≤ 4.16.92026-09-30
CVE-2026-97196 [CRITICAL] CWE-1289 CVE-2026-97196: Improper Validation of Unsafe Equivalence in Input vulnerability in Liquid Web / StellarWP GiveWP al Improper Validation of Unsafe Equivalence in Input vulnerability in Liquid Web / StellarWP GiveWP allows Authentication Bypass. This issue affects GiveWP: from n/a through 4.16.9.
nvd
CVE-2026-34900P4HIGHCVSS 7.1≥ n/a, ≤ 4.14.22026-06-15
CVE-2026-34900 [HIGH] CWE-79 CVE-2026-34900: Unauthenticated Cross Site Scripting (XSS) in GiveWP <= 4.14.2 versions. Unauthenticated Cross Site Scripting (XSS) in GiveWP <= 4.14.2 versions.
nvd
CVE-2026-104404P4MEDIUMCVSS 6.5≤ 4.17.02026-10-05
CVE-2026-104404 [MEDIUM] CWE-79 CVE-2026-104404: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability i Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Liquid Web / StellarWP GiveWP give allows Stored XSS.This issue affects GiveWP: from n/a through 4.17.0.
nvd
CVE-2023-23672P4MEDIUMCVSS 5.4≥ n/a, ≤ 2.25.12025-01-02
CVE-2023-23672 [MEDIUM] CWE-862 CVE-2023-23672: Missing Authorization vulnerability in Liquid Web / StellarWP GiveWP.This issue affects GiveWP: from Missing Authorization vulnerability in Liquid Web / StellarWP GiveWP.This issue affects GiveWP: from n/a through 2.25.1.
nvd
CVE-2026-42678P4HIGHCVSS 7.1≥ n/a, ≤ 4.14.52026-06-01
CVE-2026-42678 [HIGH] CWE-79 CVE-2026-42678: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability i Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Liquid Web / StellarWP GiveWP allows DOM-Based XSS. This issue affects GiveWP: from n/a through 4.14.5.
nvd
Liquid Web Stellarwp Givewp vulnerabilities | cvebase