First published: Mon Jul 18 2022(Updated: )
The GiveWP plugin for WordPress is vulnerable to Sensitive Information Disclosure in versions up to, and including, 2.20.2 via the /donor-wall REST-API endpoint which provides unauthenticated users with donor information even when the donor wall is not enabled. This functionality has been completely removed in version 2.20.2.
Credit: security@wordfence.com
Affected Software | Affected Version | How to fix |
---|---|---|
Givenu Givenu Give | <=2.20.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-2117 is a vulnerability in the GiveWP plugin for WordPress that allows unauthenticated users to access donor information.
The severity of CVE-2022-2117 is medium with a CVSS score of 5.3.
CVE-2022-2117 affects the GiveWP plugin by exposing donor information to unauthenticated users.
Versions up to and including 2.20.2 of the GiveWP plugin are affected by CVE-2022-2117.
To fix CVE-2022-2117, update the GiveWP plugin to version 2.21.0 or higher.