PT-2024-11920 · WordPress · Givewp

Dc11

·

Published

2024-01-16

·

Updated

2025-06-13

·

CVE-2023-0224

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions GiveWP WordPress plugin versions prior to 2.24.1
Description The issue concerns the improper escaping of user input before it reaches SQL queries, potentially allowing unauthenticated attackers to perform SQL Injection attacks.
Recommendations For versions prior to 2.24.1, update to version 2.24.1 or later to resolve the issue. As a temporary workaround, consider restricting access to sensitive database queries until the update is applied.

Exploit

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2023-0224

Affected Products

Givewp