First published: Thu Jan 02 2025(Updated: )
Missing Authorization vulnerability in Liquid Web / StellarWP GiveWP.This issue affects GiveWP: from n/a through 2.25.1.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
GiveWP | <=2.25.1 | |
GiveWP | <=2.25.1 |
Update the WordPress GiveWP plugin to the latest available version (at least 2.25.2).
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-23672 has been classified as a critical missing authorization vulnerability affecting GiveWP versions from n/a to 2.25.1.
To fix CVE-2023-23672, upgrade GiveWP to the latest version beyond 2.25.1.
CVE-2023-23672 may allow unauthorized users to perform sensitive actions due to insufficient access controls.
CVE-2023-23672 affects all GiveWP versions from n/a up to and including 2.25.1.
There is no current evidence indicating that CVE-2023-23672 is being actively exploited in the wild.