GiveWP
cpe:2.3:a:givewp:give:*:*:*:*:wordpress:*:*, +1 more
- <= 3.22.0
A vulnerability exists in the GiveWP Donation Plugin for WordPress, specifically in versions through 3.22.0. The issue arises from a missing capability check in the give_reports_earnings() function, allowing unauthenticated users to access and disclose sensitive data from earnings reports. This unauthorized access could lead to the exposure of confidential information related to donations and fundraising activities.
Exploitation of this vulnerability allows for unauthorized disclosure of sensitive earnings report data, which could include private donor information and financial details.
Users can update to GiveWP version 3.22.1 or later, where this vulnerability has been patched.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.