CVE-2020-20627
givewp givewp Missing Authentication for Critical Function
Record summary
CVE-2020-20627 has a selected CVSS score of 5.3 (medium); EIP currently links 1 Nuclei template.
Description
The includes/gateways/stripe/includes/admin/admin-actions.php in GiveWP plugin through 2.5.9 for WordPress allows unauthenticated settings change.
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Feb 2, 2023 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
givewpBrowse givewp / givewp | VulnCheck | Version data not supplied | |
Nuclei templates
1ProjectDiscoveryMEDIUMGiveWP - Missing Authorization to Settings UpdateCVSS 5.3
GiveWP plugin through 2.5.9 for WordPress contains an unauthenticated settings change caused by insecure access in includes/gateways/stripe/includes/admin/admin-actions.php, letting attackers modify settings without authentication, exploit requires no authentication.
Impact
Attackers can modify plugin settings without authentication, potentially leading to unauthorized transactions or configuration changes.
Remediation
Update to the latest version of GiveWP plugin that addresses this issue.
Source: ProjectDiscovery