GiveWP
cpe:2.3:a:givewp:give:*:*:*:*:wordpress:*:*, +1 more
- <= 3.22.1
A vulnerability allowing sensitive information exposure has been identified in the GiveWP Donation Plugin and Fundraising Platform for WordPress, affecting all versions through 3.22.1. The issue arises from a misconfigured capability check in the 'permissionsCheck' function, which allows authenticated attackers with Subscriber-level access and above to access sensitive data, including reports on donors and donation amounts.
Exploitation of this vulnerability could lead to unauthorized access to sensitive donor information and donation details.
Users can update to GiveWP version 3.22.2 or a newer patched version to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.