Input validation vulnerability in GiveWP – Donation Plugin and Fundraising Platform 3.16.1

The GiveWP donation plugin for WordPress has a security vulnerability that allows attackers to access sensitive information from the database by manipulating the ‘order’ parameter. This vulnerability affects all versions of the plugin up to version 3.16.1 and can only be exploited by authenticated attackers with GiveWP Manager-level access or higher.

Detected in:

GiveWP – Donation Plugin and Fundraising Platform fixed vulnerable versions: >= * <= 3.16.1

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.