QID 150818
Date Published: 2024-03-08
QID 150818: WordPress GiveWP Plugin: SQL Injection Vulnerability (CVE-2023-0224)
GiveWP is a WordPress plugin which allows users to create Donation and Fundraising Platform.
Affected version of GiveWP does not properly escape user input before it reaches SQL queries, which could let unauthenticated attackers perform SQL Injection attacks.
Affected Versions:
GiveWP prior to version 2.24.1
QID Detection Logic:(Unauthenticated)
This QID checks for vulnerable version of GiveWP plugin running on the target WordPress application.
Successful exploitation of this vulnerability could allow an unauthenticated attacker to perform SQL Injection attacks.
Solution
Customers are advised to upgrade to GiveWP 2.24.1 or later to remediate this vulnerability. For more information pertaining to this vulnerability please refer GiveWP Security Advisory.
Vendor References
- GiveWP Security Advisory -
givewp.com/core-2-24-0-vulnerability-patched/
CVEs related to QID 150818
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GiveWP Security Advisory |
|