Description
WordPress Plugin GiveWP-Donation and Fundraising Platform is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently modify plugin settings. WordPress Plugin GiveWP-Donation and Fundraising Platform version 2.5.9 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 2.5.10 or latest
References
Related Vulnerabilities
Claroline Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2006-4844)
WordPress Plugin Advanced Custom Fields PRO Multiple Security Bypass Vulnerabilities (5.10)
WordPress 4.0.x Multiple Vulnerabilities (4.0 - 4.0.15)
WordPress Plugin Duplicate Page Cross-Site Scripting (4.4.2)