7.5
CWE
287
Advisory Published
Updated

CVE-2019-20360

First published: Wed Jan 08 2020(Updated: )

A flaw in Give before 2.5.5, a WordPress plugin, allowed unauthenticated users to bypass API authentication methods and access personally identifiable user information (PII) including names, addresses, IP addresses, and email addresses. Once an API key has been set to any meta key value from the wp_usermeta table, and the token is set to the corresponding MD5 hash of the meta key selected, one can make a request to the restricted endpoints, and thus access sensitive donor data.

Credit: cve@mitre.org

Affected SoftwareAffected VersionHow to fix
Givewp Givewp<2.5.5

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Frequently Asked Questions

  • What is CVE-2019-20360?

    CVE-2019-20360 is a vulnerability in the Give before 2.5.5 WordPress plugin that allows unauthenticated users to bypass API authentication and access personally identifiable user information.

  • How severe is CVE-2019-20360?

    CVE-2019-20360 has a severity score of 7.5 out of 10, making it a high severity vulnerability.

  • What is affected by CVE-2019-20360?

    CVE-2019-20360 affects versions of the Give plugin before version 2.5.5.

  • How can I fix CVE-2019-20360?

    To fix CVE-2019-20360, you should update the Give plugin to version 2.5.5 or newer.

  • Where can I find more information about CVE-2019-20360?

    More information about CVE-2019-20360 can be found at the following references: [link](https://wpvulndb.com/vulnerabilities/9889) and [link](https://www.wordfence.com/blog/2019/09/authentication-bypass-vulnerability-in-givewp-plugin/).

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2024 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203