Input validation vulnerability in GiveWP – Donation Plugin and Fundraising Platform 3.4.2

The GiveWP plugin for WordPress has a security vulnerability that can be exploited by attackers. This vulnerability, known as PHP Object Injection, exists in all versions of the plugin up to 3.4.2. This means that attackers who have access to the plugin and have manager-level privileges can inject a PHP Object. However, there is no known way for attackers to exploit this vulnerability to delete files, access sensitive information, or execute code.

Detected in:

GiveWP – Donation Plugin and Fundraising Platform fixed vulnerable versions: >= * <= 3.4.2

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.