CVE-2024-5939: GiveWP – Donation Plugin and Fundraising Platform <= 3.13.0 - Missing Authorization to Limited Information Exposure
The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'setupwizard' function in all versions up to, and including, 3.13.0. This makes it possible for unauthenticated attackers to read the setup wizard administrative pages.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2024-5939?
CVE-2024-5939 is considered a significant vulnerability due to unauthorized data access resulting from a missing capability check.
How do I fix CVE-2024-5939?
To fix CVE-2024-5939, update the GiveWP – Donation Plugin and Fundraising Platform to version 3.14.0 or higher.
What are the affected versions of the GiveWP plugin for CVE-2024-5939?
CVE-2024-5939 affects all versions of the GiveWP plugin up to and including version 3.13.0.
What type of vulnerability is CVE-2024-5939?
CVE-2024-5939 is a vulnerability that allows unauthorized access to sensitive data within the GiveWP plugin.
Who impacts CVE-2024-5939?
CVE-2024-5939 primarily affects users of the GiveWP – Donation Plugin and Fundraising Platform on WordPress.