The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'handle_request' function in all versions up to, and including, 3.13.0. This makes it possible for unauthenticated attackers to edit event ticket settings if the Events beta feature is enabled.
Metrics
Affected Vendors & Products
References
History
Mon, 26 Aug 2024 18:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Givewp
Givewp givewp |
|
CPEs | cpe:2.3:a:givewp:givewp:*:*:*:*:*:wordpress:*:* | |
Vendors & Products |
Givewp
Givewp givewp |
Tue, 20 Aug 2024 14:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Webdevmattcrom
Webdevmattcrom givewp Donation Plugin And Fundraising Platform |
|
CPEs | cpe:2.3:a:webdevmattcrom:givewp_donation_plugin_and_fundraising_platform:*:*:*:*:*:*:*:* | |
Vendors & Products |
Webdevmattcrom
Webdevmattcrom givewp Donation Plugin And Fundraising Platform |
|
Metrics |
ssvc
|
Tue, 20 Aug 2024 02:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'handle_request' function in all versions up to, and including, 3.13.0. This makes it possible for unauthenticated attackers to edit event ticket settings if the Events beta feature is enabled. | |
Title | GiveWP – Donation Plugin and Fundraising Platform <= 3.13.0 - Missing Authorization to Unauthenticated Event Settings Update | |
Weaknesses | CWE-862 | |
References |
|
|
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: Wordfence
Published: 2024-08-20T02:03:19.791Z
Updated: 2024-08-20T14:14:49.953Z
Reserved: 2024-06-12T22:08:52.345Z
Link: CVE-2024-5940
Vulnrichment
Updated: 2024-08-20T13:44:52.904Z
NVD
Status : Analyzed
Published: 2024-08-20T02:15:04.793
Modified: 2024-08-26T18:14:14.083
Link: CVE-2024-5940
Redhat
No data.