CVE-2025-58842
Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in givecloud Donation Forms WP by Givecloud donation-forms-by-givecloud allows Stored XSS.This issue affects Donation Forms WP by Givecloud: from n/a through <= 1.0.9.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
A stored XSS vulnerability in Donation Forms WP by Givecloud plugin versions ≤1.0.9 allows attackers to inject malicious scripts via unescaped input.
The Wordpress plugin Donation Forms WP by Givecloud versions up to and including 1.0.9 contain an Improper Neutralization of Input During Web Page Generation vulnerability (Cross-site Scripting). The plugin fails to properly sanitize or escape user inputs when generating web pages, leading to a stored XSS flaw [1]. This means an attacker can inject arbitrary HTML and JavaScript code that persists on the server and is executed in the browsers of other users.
Exploitation requires a privileged user (e.g., an administrator) to interact with a crafted link, page, or form that triggers the injection [1]. While user interaction is needed for initial payload delivery, the malicious script then runs automatically for any site visitor, enabling broader impact. The attack surface is limited to authenticated users with sufficient privileges, but the stored nature of the XSS means a single successful injection can affect all subsequent site visitors.
A successful attack could allow a malicious actor to inject scripts that perform redirects, display advertisements, steal session cookies, or execute other HTML payloads when guests visit the compromised site [1]. This could lead to unauthorized actions, data theft, or further compromise of the WordPress installation.
The vendor has resolved the issue in version 1.0.10. Users are strongly advised to update the plugin to 1.0.10 or later [1]. For sites unable to update immediately, enabling auto-updates or seeking assistance from a hosting provider is recommended as a workaround [1].
AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2<=1.0.9+ 1 more
- (no CPE)range: <=1.0.9
- (no CPE)range: <=1.0.9
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.