QID 150818

Date Published: 2024-03-08

QID 150818: WordPress GiveWP Plugin: SQL Injection Vulnerability (CVE-2023-0224)

GiveWP is a WordPress plugin which allows users to create Donation and Fundraising Platform.

Affected version of GiveWP does not properly escape user input before it reaches SQL queries, which could let unauthenticated attackers perform SQL Injection attacks.

Affected Versions:
GiveWP prior to version 2.24.1

QID Detection Logic:(Unauthenticated)
This QID checks for vulnerable version of GiveWP plugin running on the target WordPress application.

Successful exploitation of this vulnerability could allow an unauthenticated attacker to perform SQL Injection attacks.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as Critical - 10 severity.
  • Solution
    Customers are advised to upgrade to GiveWP 2.24.1 or later to remediate this vulnerability. For more information pertaining to this vulnerability please refer GiveWP Security Advisory.
    Vendor References

    CVEs related to QID 150818

    Software Advisories
    Advisory ID Software Component Link
    GiveWP Security Advisory URL Logo givewp.com/core-2-24-0-vulnerability-patched/