CVE-2026-73357

WordPress GiveWP plugin < 4.16.6 - Cross Site Scripting (XSS) vulnerability

Donor Cross Site Scripting (XSS) in GiveWP < 4.16.6 versions.


We have discovered 31,144 live websites that are affected by CVE-2026-73357.

Run a Free Instant Scan




Affected Software

Product  GiveWP
Category Wordpress Plugins
Vulnerable Domains31,144 live websites (100% of GiveWP install base)
Vulnerable Versions
  • from 0 through 4.16.6
Vulnerable Versions Count232 versions ( 100% of all versions)


Common Weakness Enumeration

CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')



Details

  • Published - Aug 13, 2026
  • Updated - Aug 13, 2026

Credits

  • Asim Alshaya | Patchstack Bug Bounty Program (finder)

Website Distribution by Country

Number of websites using CVE-2026-73357
United States16,449 websites



Germany1,988 websites
GB1,941 websites
Italy1,272 websites
France1,112 websites
Canada882 websites
Australia622 websites
India579 websites
Cyprus548 websites
Spain542 websites

Website Distribution by TLD

Number of websites using CVE-2026-73357
.org14,315 websites
.com7,234 websites
.it843 websites
.de820 websites
.org.uk624 websites
.net564 websites
.ca502 websites
.co.uk374 websites
.fr347 websites
.nl306 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-73357

Top websites that are affected by CVE-2026-73357. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
****.org United States**,***
************.org United States**,***
*****.org United States**,***
******.org United States**,***
******************.org United States**,***
****************.org United States**,***
****************.org United States**,***
******.org United States**,***
****.info United States**,***
***********.org United States**,***
See full domain list

FAQ

CVE-2026-73357 is Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GiveWP
A total of 31,144 websites have been identified as vulnerable to CVE-2026-73357, based on global website indexing conducted by WebTechSurvey.
The GiveWP is affected by the CVE-2026-73357 vulnerability.
GiveWP versions up to 4.16.6 are vulnerable to CVE-2026-73357.
CVE-2026-73357 is resolved in version 4.16.6 of GiveWP.