CVE-2023-4248: GiveWP <= 2.33.3 - Cross-Site Request Forgery to Stripe Integration Deletion
The GiveWP plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.33.3. This is due to missing or incorrect nonce validation on the givestripedisconnectconnectstripeaccount function. This makes it possible for unauthenticated attackers to deactivate the plugin's stripe integration settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2023-4248?
CVE-2023-4248 is rated as a medium severity vulnerability due to its potential for unauthorized access.
How do I fix CVE-2023-4248?
To fix CVE-2023-4248, update the GiveWP plugin to version 2.34 or later where the vulnerability has been resolved.
Who is affected by CVE-2023-4248?
CVE-2023-4248 affects users of the GiveWP plugin for WordPress versions up to 2.33.3.
What type of vulnerability is CVE-2023-4248?
CVE-2023-4248 is a Cross-Site Request Forgery (CSRF) vulnerability.
Can CVE-2023-4248 allow an attacker to affect my website?
Yes, CVE-2023-4248 can allow an unauthenticated attacker to deactivate the Stripe payment gateway on affected websites.