Description
WordPress Plugin GiveWP-Donation and Fundraising Platform is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently bypass API authentication methods and access personally identifiable user information. WordPress Plugin GiveWP-Donation and Fundraising Platform version 2.5.4 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 2.5.5 or latest
References
Related Vulnerabilities
Vanilla Forums Improper Input Validation Vulnerability (CVE-2011-0908)
Apache HTTP Server CVE-2004-0809 Vulnerability (CVE-2004-0809)
WordPress Plugin SocialFit 'msg' Parameter Cross-Site Scripting (1.2.2)
MySQL CVE-2024-21238 Vulnerability (CVE-2024-21238)
Moodle Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2012-0796)