Extension WordPress

Vulnérabilités GiveWP – Donation Plugin and Fundraising Platform, page 3

Cette page rassemble les failles publiées pour GiveWP – Donation Plugin and Fundraising Platform, leurs plages de versions affectées et les correctifs signalés dans la base locale.

89Vulnérabilités
9Critiques
89Avec correctif
10,0CVSS maximal

Historique de sécurité

CVE et vulnérabilités de GiveWP – Donation Plugin and Fundraising Platform

89 fiches

CVE-2024-5940 Moyenne · 6,5
GiveWP – Donation Plugin and Fundraising Platform

GiveWP – Donation Plugin and Fundraising Platform <= 3.13.0 – Missing Authorization to Unauthenticated Event Settings Update

The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'handle_request' function in all versions up to, and including, 3.13.0. This makes…

Versions affectées

*-3.13.0

Correctif

3.14.0

Publication

19/08/2024

CVE-2024-5939 Moyenne · 5,3
GiveWP – Donation Plugin and Fundraising Platform

GiveWP – Donation Plugin and Fundraising Platform <= 3.13.0 – Missing Authorization to Limited Information Exposure

The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'setup_wizard' function in all versions up to, and including, 3.13.0. This makes…

Versions affectées

*-3.13.0

Correctif

3.14.0

Publication

19/08/2024

CVE-2024-5941 Moyenne · 5,4
GiveWP – Donation Plugin and Fundraising Platform

GiveWP – Donation Plugin and Fundraising Platform <= 3.14.1 – Missing Authorization to Authenticated (Subscriber+) Limited File Deletion

The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to unauthorized access and deletion of data due to a missing capability check on the 'handle_request' function in all versions up to, and including, 3.14.1.…

Versions affectées

*-3.14.1

Correctif

3.14.2

Publication

19/08/2024

CVE-2024-5977 Moyenne · 5,4
GiveWP – Donation Plugin and Fundraising Platform

GiveWP – Donation Plugin and Fundraising Platform <= 3.13.0 – Insecure Direct Object Reference to Authenticated (GiveWP Worker+) Arbitrary Post Actions

The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.13.0 via the 'handleRequest' function due to missing validation on a user controlled…

Versions affectées

*-3.13.0

Correctif

3.14.0

Publication

18/07/2024

CVE-2024-35679 Moyenne · 6,1
GiveWP – Donation Plugin and Fundraising Platform

GiveWP – Donation Plugin and Fundraising Platform <= 3.12.0 – Reflected Cross-Site Scripting

The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, 3.12.0 due to insufficient input sanitization and output escaping. This makes it possible for…

Versions affectées

*-3.12.0

Correctif

3.12.1

Publication

06/06/2024

CVE-2024-3714 Moyenne · 6,4
GiveWP – Donation Plugin and Fundraising Platform

GiveWP – Donation Plugin and Fundraising Platform <= 3.10.0 – Authenticated (Contributor+) Stored Cross-Site Scripting

The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'give_form' shortcode when used with a legacy form in all versions up to, and including, 3.10.0 due to…

Versions affectées

*-3.10.0

Correctif

3.11.0

Publication

17/05/2024

CVE-2024-30229 Élevée · 8,8
GiveWP – Donation Plugin and Fundraising Platform

GiveWP – Donation Plugin and Fundraising Platform <= 3.4.2 – Authenticated (GiveWP Manager+) PHP Object Injection

The GiveWP plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.4.2 via deserialization of untrusted input. This makes it possible for authenticated attackers, with give manager-level access and above, to…

Versions affectées

*-3.4.2

Correctif

3.5.0

Publication

26/04/2024

CVE-2024-1957 Moyenne · 6,4
GiveWP – Donation Plugin and Fundraising Platform

GiveWP – Donation Plugin and Fundraising Platform <= 3.6.1 — Authenticated(Contributor+) Stored Cross-Site Scripting via Shortcode

The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'give_form' shortcode in all versions up to, and including, 3.6.1 due to insufficient input sanitization and output escaping…

Versions affectées

*-3.6.1

Correctif

3.7.0

Publication

12/04/2024

CVE-2024-1424 Moyenne · 6,4
GiveWP – Donation Plugin and Fundraising Platform

GiveWP – Donation Plugin and Fundraising Platform <= 3.5.1 – Authenticated (Contributor+) Stored Cross-Site Scripting

The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 3.5.1 due to insufficient input sanitization and output escaping on…

Versions affectées

*-3.5.1

Correctif

3.6.0

Publication

19/03/2024

CVE-2023-51415 Moyenne · 6,4
GiveWP – Donation Plugin and Fundraising Platform

GiveWP <= 3.2.2 – Authenticated (Contributor+) Stored Cross-Site Scripting

The GiveWP plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.2.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above,…

Versions affectées

*-3.2.2

Correctif

3.3.0

Publication

19/01/2024

CVE-2023-4247 Moyenne · 5,4
GiveWP – Donation Plugin and Fundraising Platform

GiveWP <= 2.33.3 – Cross-Site Request Forgery to plugin deactivation

The GiveWP plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.33.3. This is due to missing or incorrect nonce validation on the give_sendwp_disconnect function. This makes it possible for unauthenticated attackers…

Versions affectées

*-2.33.3

Correctif

2.33.4

Publication

31/10/2023

CVE-2023-4246 Moyenne · 4,3
GiveWP – Donation Plugin and Fundraising Platform

GiveWP <= 2.33.3 – Cross-Site Request Forgery to plugin installation

The GiveWP plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.33.3. This is due to missing or incorrect nonce validation on the give_sendwp_remote_install_handler function. This makes it possible for unauthenticated attackers…

Versions affectées

*-2.33.3

Correctif

2.33.4

Publication

31/10/2023

CVE-2023-4248 Moyenne · 5,4
GiveWP – Donation Plugin and Fundraising Platform

GiveWP <= 2.33.3 – Cross-Site Request Forgery to Stripe Integration Deletion

The GiveWP plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.33.3. This is due to missing or incorrect nonce validation on the give_stripe_disconnect_connect_stripe_account function. This makes it possible for unauthenticated attackers…

Versions affectées

*-2.33.3

Correctif

2.33.4

Publication

31/10/2023

CVE-2023-41665 Élevée · 7,2
GiveWP – Donation Plugin and Fundraising Platform

Give – Donation Plugin <= 2.33.0 – Authenticated(Give Manager+) Privilege Escalation

The Give – Donation Plugin plugin for WordPress is vulnerable to privilege escalation due to an insufficient capability check when updating default roles in versions up to, and including, 2.33.0. This makes it possible for authenticated attackers with…

Versions affectées

[*, 2.33.1)

Correctif

2.33.1

Publication

31/08/2023

CVE-2023-32513 Moyenne · 6,6
GiveWP – Donation Plugin and Fundraising Platform

GiveWP <= 2.25.3 – Authenticated (Admin+) PHP Object Injection

The GiveWP plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.25.3 via deserialization of untrusted input via the $output['main_key'] value. This allows authenticated attackers, with administrative privileges, to inject a PHP…

Versions affectées

*-2.25.3

Correctif

2.26.0

Publication

10/05/2023

Vulnérabilité Moyenne · 5,3
GiveWP – Donation Plugin and Fundraising Platform

GiveWP <= 2.25.2 – Cross-Site Request Forgery via give_ajax_store_payment_note

The GiveWP for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.25.2. This is due to missing or incorrect nonce validation on the give_ajax_store_payment_note function. This makes it possible for unauthenticated attackers to…

Versions affectées

*-2.25.2

Correctif

2.25.3

Publication

23/03/2023

Vulnérabilité Moyenne · 5,3
GiveWP – Donation Plugin and Fundraising Platform

GiveWP <= 2.25.2 – Cross-Site Request Forgery via give_ajax_delete_payment_note

The GiveWP for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.25.2. This is due to missing or incorrect nonce validation on the give_ajax_delete_payment_note function. This makes it possible for unauthenticated attackers to…

Versions affectées

*-2.25.2

Correctif

2.25.3

Publication

23/03/2023

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités