The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.13.0 via the 'handleRequest' function due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with GiveWP Worker-level access and above, to delete and update arbitrary posts.
Advisories
Source ID Title
EUVD EUVD EUVD-2024-47097 The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.13.0 via the 'handleRequest' function due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with GiveWP Worker-level access and above, to delete and update arbitrary posts.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2024-08-01T21:25:03.226Z

Reserved: 2024-06-13T17:25:30.236Z

Link: CVE-2024-5977

cve-icon Vulnrichment

Updated: 2024-08-01T21:25:03.226Z

cve-icon NVD

Status : Modified

Published: 2024-07-19T11:15:03.873

Modified: 2024-11-21T09:48:40.960

Link: CVE-2024-5977

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.