Vulnerability CVE-2024-5939


Published: 2024-08-20

Description:
The GiveWP ?? Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'setup_wizard' function in all versions up to, and including, 3.13.0. This makes it possible for unauthenticated attackers to read the setup wizard administrative pages.

 References:
https://www.wordfence.com/threat-intel/vulnerabilities/id/a104f88b-deae-465d-b4c1-9a1fc78e5ee9?source=cve
https://plugins.trac.wordpress.org/browser/give/tags/3.12.0/src/Onboarding/Wizard/Page.php#L78
https://plugins.trac.wordpress.org/changeset/3120745/

Copyright 2026, cxsecurity.com

 

Back to Top