PT-2022-14899 · WordPress · Givewp

Kane Gamble

·

Published

2022-07-18

·

Updated

2024-01-11

·

CVE-2022-2117

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions GiveWP plugin for WordPress versions up to, and including, 2.20.2
Description The issue allows unauthenticated users to access donor information through the "/donor-wall" REST-API endpoint, even when the donor wall is not enabled. This functionality has been removed in version 2.20.2.
Recommendations For versions up to, and including, 2.20.2, update to a version where this functionality has been removed, such as version 2.20.2 or later, to prevent unauthenticated access to donor information via the "/donor-wall" REST-API endpoint. As a temporary workaround, consider disabling the "/donor-wall" REST-API endpoint until a patch is available.

Fix

Information Disclosure

Weakness Enumeration

Related Identifiers

CVE-2022-2117

Affected Products

Givewp