CVE-2023-0224: GiveWP < 2.24.1 - Unauthenticated SQLi
Published Jan 16, 2024
·Updated
The GiveWP WordPress plugin before 2.24.1 does not properly escape user input before it reaches SQL queries, which could let unauthenticated attackers perform SQL Injection attacks
Affected Software
1 affected component
GiveWP GiveWP WordPress<2.24.1
Event History
Jan 16, 2024
CVE Published
via MITRE·03:54 PM
Data Sourced
via MITRE·03:54 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2023-0224?
CVE-2023-0224 has a high severity rating due to its potential for SQL Injection attacks.
2
How do I fix CVE-2023-0224?
To fix CVE-2023-0224, update the GiveWP WordPress plugin to version 2.24.1 or later.
3
Who is affected by CVE-2023-0224?
CVE-2023-0224 affects installations of the GiveWP WordPress plugin prior to version 2.24.1.
4
What type of vulnerability is CVE-2023-0224?
CVE-2023-0224 is an SQL Injection vulnerability that can allow unauthorized access to the database.
5
Can CVE-2023-0224 be exploited by unauthenticated users?
Yes, CVE-2023-0224 can be exploited by unauthenticated attackers, increasing its risk.