CVE-2022-31475: WordPress GiveWP plugin <= 2.20.2 - Authenticated Arbitrary File Read via Export function vulnerability
Published Jul 21, 2022
·Updated
Authenticated (custom plugin role) Arbitrary File Read via Export function vulnerability in GiveWP's GiveWP plugin <= 2.20.2 at WordPress.
Affected Software
1 affected component
GiveWP GiveWP WordPress<2.21.0
Remediation
Information
Update to 2.21.0 or higher version.
Event History
Jul 21, 2022
CVE Published
via MITRE·05:24 PM
Data Sourced
via MITRE·05:24 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2022-31475.
2
What is the title of this vulnerability?
The title of this vulnerability is Authenticated (custom plugin role) Arbitrary File Read via Export function vulnerability in GiveWP's GiveWP plugin <= 2.20.2 at WordPress.
3
What is the affected software?
The affected software is GiveWP's GiveWP plugin <= 2.20.2 at WordPress.
4
What is the severity of this vulnerability?
The severity of this vulnerability is medium.
5
How do I fix this vulnerability?
To fix this vulnerability, update GiveWP plugin to version 2.21.0 or later.