CVE-2022-2117

MEDIUM

GiveWP < 2.20.2 - Unauthenticated Sensitive Information Disclosure via Donor Wall REST-API Endpoint

Title source: llm
STIX 2.1

Description

The GiveWP plugin for WordPress is vulnerable to Sensitive Information Disclosure in versions up to, and including, 2.20.2 via the /donor-wall REST-API endpoint which provides unauthenticated users with donor information even when the donor wall is not enabled. This functionality has been completely removed in version 2.20.2.

Scores

CVSS v3 5.3
EPSS 0.0091
EPSS Percentile 55.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Details

CWE
CWE-200
Status published
Products (2)
givewp/givewp < 2.20.2
stellarwp/GiveWP – Donation Plugin and Fundraising Platform < 2.20.2
Published Jul 18, 2022
Tracked Since Feb 18, 2026