Impact
The GiveWP plugin for WordPress has a vulnerability that allows attackers to perform a cross‑site request forgery attack by sending a forged request to the give_set_notification_status_handler() function. Because a nonce is not validated, an unauthenticated attacker can cause a site administrator to open or trigger a crafted link that disables email notifications for donations, resulting in the loss of critical donor communication and potentially affecting the plugin’s integrity and functionality.
Affected Systems
All installations of the GiveWP Donation Plugin and Fundraising Platform up to and including version 4.15.3, distributed by stellarwp, are affected. A user’s WordPress site running any of these versions can be compromised through the plugin’s AJAX endpoint.
Risk and Exploitability
The CVSS score of 4.3 indicates a medium severity. An attacker must trick an authenticated administrator into executing the malicious request, so the attack vector is user interaction. No EPSS data is available, and the vulnerability is not listed in CISA’s KEV catalog. The missing nonce check makes this flaw straightforward to exploit once a target user is lured to click a link, which can be achieved via phishing or social engineering.
OpenCVE Enrichment