CVE-2022-40312: WordPress GiveWP Plugin <= 2.25.1 is vulnerable to Server Side Request Forgery (SSRF)
Published Dec 18, 2023
·Updated
Server-Side Request Forgery (SSRF) vulnerability in GiveWP GiveWP – Donation Plugin and Fundraising Platform.This issue affects GiveWP – Donation Plugin and Fundraising Platform: from n/a through 2.25.1.
Affected Software
1 affected component
GiveWP GiveWP WordPress<=2.25.1
Remediation
Information
Update to 2.25.2 or a higher version.
Event History
Dec 18, 2023
CVE Published
via MITRE·03:08 PM
Data Sourced
via MITRE·03:08 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2022-40312?
CVE-2022-40312 is classified as a Server-Side Request Forgery (SSRF) vulnerability in the GiveWP Donation Plugin.
2
How do I fix CVE-2022-40312?
To mitigate CVE-2022-40312, update the GiveWP Donation Plugin to version 2.25.2 or later.
3
What versions are affected by CVE-2022-40312?
CVE-2022-40312 affects GiveWP – Donation Plugin versions from n/a through 2.25.1.
4
What are the potential risks of CVE-2022-40312?
CVE-2022-40312 could allow an attacker to perform unauthorized actions by manipulating server requests.
5
Is CVE-2022-40312 specific to any platform?
Yes, CVE-2022-40312 specifically affects the GiveWP Donation Plugin on WordPress.