The GiveWP plugin for WordPress is vulnerable to Sensitive Information Disclosure in versions up to, and including, 2.20.2 via the /donor-wall REST-API endpoint which provides unauthenticated users with donor information even when the donor wall is not enabled. This functionality has been completely removed in version 2.20.2.
References
Configurations
History
11 Jan 2024, 09:15
Type | Values Removed | Values Added |
---|---|---|
CWE | ||
References |
|
Information
Published : 2022-07-18 17:15
Updated : 2024-02-28 19:29
NVD link : CVE-2022-2117
Mitre link : CVE-2022-2117
CVE.ORG link : CVE-2022-2117
JSON object : View
Products Affected
givewp
- givewp
CWE
No CWE.