CVE-2023-23672: WordPress GiveWP plugin <= 2.25.1 - Arbitrary Content Deletion vulnerability
Published Jan 2, 2025
·Updated
Missing Authorization vulnerability in Liquid Web / StellarWP GiveWP.This issue affects GiveWP: from n/a through 2.25.1.
Affected Software
3 affected components
Liquid Web GiveWP<=2.25.1
WordPress GiveWP<=2.25.1
GiveWP GiveWP WordPress<2.25.2
Remediation
Information
Update the WordPress GiveWP plugin to the latest available version (at least 2.25.2).
Event History
Jan 2, 2025
CVE Published
via MITRE·03:06 PM
Data Sourced
via MITRE·03:06 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-23672?
CVE-2023-23672 has been classified as a critical missing authorization vulnerability affecting GiveWP versions from n/a to 2.25.1.
2
How do I fix CVE-2023-23672?
To fix CVE-2023-23672, upgrade GiveWP to the latest version beyond 2.25.1.
3
What impact does CVE-2023-23672 have on my system?
CVE-2023-23672 may allow unauthorized users to perform sensitive actions due to insufficient access controls.
4
Which versions of GiveWP are affected by CVE-2023-23672?
CVE-2023-23672 affects all GiveWP versions from n/a up to and including 2.25.1.
5
Is CVE-2023-23672 being actively exploited?
There is no current evidence indicating that CVE-2023-23672 is being actively exploited in the wild.