Description
The GiveWP plugin for WordPress is vulnerable to Sensitive Information Disclosure in versions up to, and including, 2.20.2 via the /donor-wall REST-API endpoint which provides unauthenticated users with donor information even when the donor wall is not enabled. This functionality has been completely removed in version 2.20.2.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-34403 | The GiveWP plugin for WordPress is vulnerable to Sensitive Information Disclosure in versions up to, and including, 2.20.2 via the /donor-wall REST-API endpoint which provides unauthenticated users with donor information even when the donor wall is not enabled. This functionality has been completely removed in version 2.20.2. |
References
History
Wed, 08 Apr 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | GiveWP – Donation Plugin and Fundraising Platform <= 2.20.2 - Sensitive Information Disclosure | |
| Weaknesses | CWE-200 |
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-04-08T17:15:13.774Z
Reserved: 2022-06-17T00:00:00.000Z
Link: CVE-2022-2117
No data.
Status : Modified
Published: 2022-07-18T17:15:09.007
Modified: 2026-04-08T19:17:50.817
Link: CVE-2022-2117
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD