CVE-2022-28700: WordPress GiveWP plugin <= 2.20.2 - Authenticated Arbitrary File Creation via Export function vulnerability
Published Jul 21, 2022
·Updated
Authenticated Arbitrary File Creation via Export function vulnerability in GiveWP's GiveWP plugin <= 2.20.2 at WordPress.
Affected Software
1 affected component
GiveWP GiveWP WordPress<2.21.0
Remediation
Information
Update to 2.21.0 or higher version.
Event History
Jul 21, 2022
CVE Published
via MITRE·05:23 PM
Data Sourced
via MITRE·05:23 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·06:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2022-28700.
2
What is the title of this vulnerability?
The title of this vulnerability is "Authenticated Arbitrary File Creation via Export function vulnerability in GiveWP's GiveWP plugin <= 2.20.2 at WordPress."
3
What is the severity of CVE-2022-28700?
The severity of CVE-2022-28700 is critical (7.2).
4
What software is affected by this vulnerability?
The GiveWP plugin version <= 2.20.2 at WordPress is affected by this vulnerability.
5
How can I fix CVE-2022-28700?
To fix CVE-2022-28700, update the GiveWP plugin to version 2.21.0 or higher.