CVE-2019-13578: SQL Injection
Published Aug 15, 2019
·Updated
A SQL injection vulnerability exists in the Impress GiveWP Give plugin through 2.5.0 for WordPress. Successful exploitation of this vulnerability would allow a remote attacker to execute arbitrary SQL commands on the affected system via includes/payments/class-payments-query.php.
Affected Software
1 affected component
GiveWP GiveWP WordPress<=2.5.0
Remediation
Event History
Aug 15, 2019
CVE Published
via MITRE·03:36 PM
Data Sourced
via MITRE·03:36 PM
Description
Frequently Asked Questions
1
What is the CVE ID of this vulnerability?
The CVE ID of this vulnerability is CVE-2019-13578.
2
What is the affected software?
The affected software is the Impress GiveWP Give plugin through version 2.5.0 for WordPress.
3
What is the severity of CVE-2019-13578?
The severity of CVE-2019-13578 is critical with a CVSS score of 9.8.
4
How can this vulnerability be exploited?
This vulnerability can be exploited by a remote attacker to execute arbitrary SQL commands on the affected system.
5
Is there a fix available for this vulnerability?
Yes, a fix is available through the latest version of the Impress GiveWP Give plugin.