Description
WordPress Plugin GiveWP-Donation and Fundraising Platform is prone to an information disclosure vulnerability. Attackers can exploit this issue to obtain sensitive information that may help in launching further attacks. WordPress Plugin GiveWP-Donation and Fundraising Platform version 2.20.2 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 2.21.0 or latest
References
Related Vulnerabilities
WordPress Permissions, Privileges, and Access Controls Vulnerability (CVE-2008-3747)
PHP Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2011-3379)
MySQL CVE-2019-2503 Vulnerability (CVE-2019-2503)
WordPress Plugin Image Optimizer, Resizer and CDN-Sirv Cross-Site Scripting (6.8.0)