The GiveWP plugin for WordPress is vulnerable to Sensitive Information Disclosure in versions up to, and including, 2.20.2 via the /donor-wall REST-API endpoint which provides unauthenticated users with donor information even when the donor wall is not enabled. This functionality has been completely removed in version 2.20.2.
References
Configurations
History
25 Jul 2022, 16:52
Type | Values Removed | Values Added |
---|---|---|
References | (MISC) https://www.wordfence.com/vulnerability-advisories/#CVE-2022-2117 - Third Party Advisory | |
References | (MISC) https://plugins.trac.wordpress.org/changeset/2743833/give/tags/2.21.0/includes/api/class-give-api-v2.php - Third Party Advisory | |
CPE | cpe:2.3:a:givewp:givewp:*:*:*:*:*:wordpress:*:* | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 5.3 |
18 Jul 2022, 17:51
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2022-07-18 17:15
Updated : 2024-02-04 22:51
NVD link : CVE-2022-2117
Mitre link : CVE-2022-2117
CVE.ORG link : CVE-2022-2117
JSON object : View
Products Affected
givewp
- givewp
CWE
No CWE.