What the vulnerability does
01Description
Authenticated (custom plugin role) Arbitrary File Read via Export function vulnerability in GiveWP's GiveWP plugin <= 2.20.2 at WordPress.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:N
What the vulnerability does
Authenticated (custom plugin role) Arbitrary File Read via Export function vulnerability in GiveWP's GiveWP plugin <= 2.20.2 at WordPress.
Explanation of Vulnerability in Simple Terms
GiveWP versions up to 2.20.2 contain a flaw allowing high-privilege users to read sensitive data they should not access. An administrator or donor manager can view confidential information and make limited unauthorized changes. The vulnerability requires an authenticated account with elevated permissions and does not affect site availability.
What an attacker can do
Read sensitive data and make limited unauthorized modifications as a high-privilege user.
Potential impact on your site
Admins or donor managers could access confidential donor or financial data beyond their intended scope.
Conditions required to exploit
Attacker must have an authenticated admin or manager account on the WordPress site.
Key dates
External resources