First published: Mon Aug 31 2020(Updated: )
The includes/gateways/stripe/includes/admin/admin-actions.php in GiveWP plugin through 2.5.9 for WordPress allows unauthenticated settings change.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Givenu Givenu Give | <=2.5.9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of this vulnerability is CVE-2020-20627.
The title of this vulnerability is 'The includes/gateways/stripe/includes/admin/admin-actions.php in GiveWP plugin through 2.5.9 for WordPress allows unauthenticated settings change.'
The severity level of this vulnerability is medium.
The affected software for this vulnerability is GiveWP plugin through version 2.5.9 for WordPress.
The CWE ID for this vulnerability is CWE-306.