Extension WordPress

Vulnérabilités GiveWP – Donation Plugin and Fundraising Platform, page 4

Cette page rassemble les failles publiées pour GiveWP – Donation Plugin and Fundraising Platform, leurs plages de versions affectées et les correctifs signalés dans la base locale.

77Vulnérabilités
8Critiques
77Avec correctif
10,0CVSS maximal

Historique de sécurité

CVE et vulnérabilités de GiveWP – Donation Plugin and Fundraising Platform

77 fiches

CVE-2022-2215 Moyenne · 5,5
GiveWP – Donation Plugin and Fundraising Platform

GiveWP <= 2.21.2 – Authenticated (Admin+) Stored Cross-Site Scripting

The GiveWP WordPress plugin before 2.21.3 does not properly sanitise and escape the currency settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks when the unfiltered_html capability is disallowed (for example…

Versions affectées

*-2.21.2

Correctif

2.21.3

Publication

11/07/2022

CVE-2022-2260 Moyenne · 4,3
GiveWP – Donation Plugin and Fundraising Platform

GiveWP – Donation Plugin and Fundraising Platform <= 2.21.2 – Cross-Site Request Forgery

The GiveWP plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.21.2. This is due to missing or incorrect nonce validation on the can_export function. This makes it possible for unauthenticated attackers…

Versions affectées

*-2.21.2

Correctif

2.21.3

Publication

08/07/2022

CVE-2022-2117 Moyenne · 5,3
GiveWP – Donation Plugin and Fundraising Platform

GiveWP – Donation Plugin and Fundraising Platform <= 2.20.2 – Sensitive Information Disclosure

The GiveWP plugin for WordPress is vulnerable to Sensitive Information Disclosure in versions up to, and including, 2.20.2 via the /donor-wall REST-API endpoint which provides unauthenticated users with donor information even when the donor wall is not enabled.…

Versions affectées

*-2.20.2

Correctif

2.21.0

Publication

17/06/2022

CVE-2019-13578 Critique · 9,8
GiveWP – Donation Plugin and Fundraising Platform

GiveWP – Donation Plugin and Fundraising Platform <= 2.5.0 – SQL Injection

A SQL injection vulnerability exists in the Impress GiveWP Give plugin through 2.5.0 for WordPress. Successful exploitation of this vulnerability would allow a remote attacker to execute arbitrary SQL commands on the affected system via includes/payments/class-payments-query.php.

Versions affectées

*-2.5.0

Correctif

2.5.1

Publication

12/08/2019

Vulnérabilité Moyenne · 6,1
GiveWP – Donation Plugin and Fundraising Platform

GiveWP – Donation Plugin and Fundraising Platform < 0.8.5 – Reflected Cross-Site Scripting

The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Cross-Site Scripting in versions before 0.8.5 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web…

Versions affectées

[*, 0.8.5)

Correctif

0.8.5

Publication

20/04/2015

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités