GiveWP WordPress Plugin Unauthenticated Earnings Report Information Disclosure
The GiveWP – Donation Plugin and Fundraising Platform for WordPress contains a security vulnerability in the give_reports_earnings() function across all versions up to and including 3.22.0. The issue stems from a lack of proper capability verification, which enables unauthenticated attackers to access and disclose sensitive earnings report information without requiring any valid user credentials.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
givewp givewp – donation plugin and fundraising platform |
||
givewp givewp |