CVE-2023-25450: WordPress GiveWP Plugin <= 2.25.1 is vulnerable to Cross Site Request Forgery (CSRF)
Cross-Site Request Forgery (CSRF) vulnerability in GiveWP GiveWP – Donation Plugin and Fundraising Platform plugin <= 2.25.1 versions.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the vulnerability ID for the Cross-Site Request Forgery (CSRF) vulnerability in GiveWP GiveWP – Donation Plugin and Fundraising Platform plugin?
The vulnerability ID is CVE-2023-25450.
What is the severity of CVE-2023-25450?
CVE-2023-25450 has a severity level of 8.8 (high).
Which version of the GiveWP GiveWP – Donation Plugin and Fundraising Platform plugin is affected by CVE-2023-25450?
CVE-2023-25450 affects versions <= 2.25.1 of the GiveWP GiveWP – Donation Plugin and Fundraising Platform plugin.
How can I fix the Cross-Site Request Forgery (CSRF) vulnerability in GiveWP GiveWP – Donation Plugin and Fundraising Platform plugin?
To fix the vulnerability, update the GiveWP GiveWP – Donation Plugin and Fundraising Platform plugin to version 2.25.2 or higher.
Is there any reference for CVE-2023-25450?
Yes, you can find more information about CVE-2023-25450 at this link: [https://patchstack.com/database/vulnerability/give/wordpress-givewp-plugin-2-25-1-cross-site-request-forgery-csrf-via-give-cache-flush-vulnerability?_s_id=cve](https://patchstack.com/database/vulnerability/give/wordpress-givewp-plugin-2-25-1-cross-site-request-forgery-csrf-via-give-cache-flush-vulnerability?_s_id=cve)