Input validation vulnerability in GiveWP – Donation Plugin and Fundraising Platform 4.13.0

The GiveWP plugin for WordPress, which helps with donations and fundraising, has a security issue that can be exploited by hackers. This is because the plugin does not properly clean and protect user input, allowing attackers to add their own code to web pages. This can affect any version of the plugin up to 4.13.0 and can be done by anyone without needing to log in. However, for the attack to work, avatars must be turned on in the WordPress site.

Detected in:

GiveWP – Donation Plugin and Fundraising Platform fixed vulnerable versions: >= * <= 4.13.0

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.