The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.13.0 via the 'handleRequest' function due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with GiveWP Worker-level access and above, to delete and update arbitrary posts.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published: 2024-07-19T11:01:41.290Z

Updated: 2024-08-01T21:25:03.226Z

Reserved: 2024-06-13T17:25:30.236Z

Link: CVE-2024-5977

cve-icon Vulnrichment

Updated: 2024-08-01T21:25:03.226Z

cve-icon NVD

Status : Analyzed

Published: 2024-07-19T11:15:03.873

Modified: 2024-07-19T18:27:34.967

Link: CVE-2024-5977

cve-icon Redhat

No data.