PT-2020-15274 · Wordimpress · Givewp

Published

2020-08-31

·

Updated

2025-12-09

·

CVE-2020-20627

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions GiveWP plugin versions prior to 2.5.10
Description The issue allows unauthenticated changes to settings. This is due to a problem in the includes/gateways/stripe/includes/admin/admin-actions.php file.
Recommendations For GiveWP plugin versions prior to 2.5.10, update to version 2.5.10 or later to resolve the issue.

Fix

Missing Authentication

Weakness Enumeration

Related Identifiers

CVE-2020-20627

Affected Products

Givewp