Input validation vulnerability in GiveWP – Donation Plugin and Fundraising Platform 3.19.2

The donation plugin for WordPress called GiveWP is at risk of being attacked by hackers in versions up to 3.19.2. This can happen through the donation form where someone can enter their first name. This allows hackers to inject a harmful code onto the server. Even though a patch was released in version 3.19.3, it was not enough to fully fix the issue. Another organization has also identified the same problem in version 3.19.3, so it still affects versions 3.19.2 and earlier. To prevent this from happening, it is recommended that the vendor uses a different type of coding called JSON encoding.

Detected in:

GiveWP – Donation Plugin and Fundraising Platform fixed vulnerable versions: >= * <= 3.19.2

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.