RSS   Vulnerabilities for 'Givewp'   RSS

2022-02-21
 
CVE-2021-25099

CWE-79
 

 
The GiveWP WordPress plugin before 2.17.3 does not sanitise and escape the form_id parameter before outputting it back in the response of an unauthenticated request via the give_checkout_login AJAX action, leading to a Reflected Cross-Site Scripting

 
 
CVE-2021-25100

CWE-79
 

 
The GiveWP WordPress plugin before 2.17.3 does not escape the s parameter before outputting it back in an attribute in the Donation Forms dashboard, leading to a Reflected Cross-Site Scripting

 
 
CVE-2022-0252

CWE-79
 

 
The GiveWP WordPress plugin before 2.17.3 does not escape the json parameter before outputting it back in an attribute in the Import admin dashboard, leading to a Reflected Cross-Site Scripting

 
2021-08-23
 
CVE-2021-24524

CWE-79
 

 
The GiveWP ??�??�?? Donation Plugin and Fundraising Platform WordPress plugin before 2.12.0 did not escape the Donation Level setting of its Donation Forms, allowing high privilege users to use Cross-Site Scripting payloads in them.

 
2020-08-31
 
CVE-2020-20627

CWE-306
 

 
The includes/gateways/stripe/includes/admin/admin-actions.php in GiveWP plugin through 2.5.9 for WordPress allows unauthenticated settings change.

 

 >>> Vendor: Givewp 2 Products
GIVE
Givewp


Copyright 2024, cxsecurity.com

 

Back to Top