Description
A SQL injection vulnerability exists in the Impress GiveWP Give plugin through 2.5.0 for WordPress. Successful exploitation of this vulnerability would allow a remote attacker to execute arbitrary SQL commands on the affected system via includes/payments/class-payments-query.php.
References (5)
Core 5
Core References
Patch, Third Party Advisory x_refsource_misc
https://github.com/impress-org/give/commit/d91f4c6dcc92aeb826b060cb2feadd56885f4cea
Patch, Third Party Advisory x_refsource_misc
https://github.com/impress-org/give/commit/97b9b5fae2d10742ee42fe00092729fa7da3cb32
Third Party Advisory x_refsource_misc
https://wpvulndb.com/vulnerabilities/9504
Patch, Third Party Advisory x_refsource_misc
https://github.com/impress-org/give/commit/894937d7927eab0c98457656cbd6fb414b3a6fbf
Third Party Advisory x_refsource_misc
https://fortiguard.com/zeroday/FG-VD-19-098
Scores
CVSS v3
9.8
EPSS
0.0289
EPSS Percentile
85.2%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-89
Status
published
Products (1)
givewp/givewp
< 2.5.0
Published
Aug 15, 2019
Tracked Since
Feb 18, 2026