Output validation vulnerability in GiveWP – Donation Plugin and Fundraising Platform 2.25.3

The GiveWP plugin for WordPress is vulnerable to a security issue. Versions up to and including 2.25.3 are affected. This plugin is used to add features to a WordPress website. The security issue is called “PHP Object Injection”. It occurs when an attacker with administrative privileges is able to inject an object into the plugin. This object can be used to delete files, access sensitive data or execute code. The plugin itself does not have any additional security measures, so if any are present on the system they could be exploited.

Detected in:

GiveWP – Donation Plugin and Fundraising Platform fixed vulnerable versions: >= * <= 2.25.3

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.