What the vulnerability does
01Description
Cross-Site Request Forgery (CSRF) vulnerability in GiveWP GiveWP – Donation Plugin and Fundraising Platform plugin <= 2.25.1 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L
What the vulnerability does
Cross-Site Request Forgery (CSRF) vulnerability in GiveWP GiveWP – Donation Plugin and Fundraising Platform plugin <= 2.25.1 versions.
Explanation of Vulnerability in Simple Terms
GiveWP versions up to 2.25.1 are vulnerable to cross-site request forgery (CSRF) attacks. An attacker can craft a malicious webpage that, when visited by a logged-in site administrator, performs unwanted actions on the donation plugin without the admin's knowledge or consent. This could allow modification of donation settings or other plugin configurations.
What an attacker can do
Trick a logged-in admin into performing unwanted actions on the donation plugin via a malicious webpage.
Potential impact on your site
Donation settings or plugin configuration could be altered without your knowledge if an admin visits a compromised site.
Conditions required to exploit
Admin must visit a malicious webpage while logged into the WordPress site.
Key dates
External resources
Related vulnerabilities