Record summary

CVE-2020-20627 has a selected CVSS score of 5.3 (medium); EIP currently links 1 Nuclei template.

Description

The includes/gateways/stripe/includes/admin/admin-actions.php in GiveWP plugin through 2.5.9 for WordPress allows unauthenticated settings change.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Feb 2, 2023 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

Affected products and versions

1
ProductSourceVersion rangeStatus
VulnCheckVersion data not supplied

Nuclei templates

1
ProjectDiscoveryMEDIUMGiveWP - Missing Authorization to Settings UpdateCVSS 5.3

GiveWP plugin through 2.5.9 for WordPress contains an unauthenticated settings change caused by insecure access in includes/gateways/stripe/includes/admin/admin-actions.php, letting attackers modify settings without authentication, exploit requires no authentication.

Impact

Attackers can modify plugin settings without authentication, potentially leading to unauthorized transactions or configuration changes.

Remediation

Update to the latest version of GiveWP plugin that addresses this issue.

WeaknessesCWE-306
Authorsdaffainfo
Template tagscvecve2020wpwordpresswp-plugingivewpunauthintrusivevkev
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
CPE: cpe:2.3:a:givewp:givewp:*:*:*:*:*:wordpress:*:*
Shodan: http.html:"/wp-content/plugins/give/"
FOFA: body="/wp-content/plugins/give/"

Source: ProjectDiscovery

References

2