CVE-2024-47315: WordPress GiveWP – Donation Plugin and Fundraising Platform plugin <= 3.15.1 - Cross Site Request Forgery (CSRF) vulnerability
Published Sep 25, 2024
·Updated
Cross-Site Request Forgery (CSRF) vulnerability in StellarWP GiveWP give.This issue affects GiveWP: from n/a through <= 3.15.1.
Affected Software
1 affected component
GiveWP GiveWP WordPress<3.16.0
Remediation
Information
Update to 3.16.0 or a higher version.
Event History
Sep 25, 2024
CVE Published
via MITRE·05:32 PM
Data Sourced
via MITRE·05:32 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-47315?
CVE-2024-47315 has been classified as a Cross-Site Request Forgery (CSRF) vulnerability affecting GiveWP versions up to 3.15.1.
2
How do I fix CVE-2024-47315?
To fix CVE-2024-47315, upgrade your GiveWP plugin to version 3.16.0 or later.
3
What versions are affected by CVE-2024-47315?
CVE-2024-47315 affects GiveWP versions from n/a through 3.15.1.
4
What is the impact of CVE-2024-47315?
CVE-2024-47315 allows attackers to perform actions on behalf of an authenticated user without their consent.
5
Is there any workaround for CVE-2024-47315?
Currently, the only recommended solution for CVE-2024-47315 is to update to the latest version of GiveWP.