nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2022-28700 CVE-2022-28700
CRITICAL
WordPress GiveWP plugin <= 2.20.2 - Authenticated Arbitrary File Creation via Export function vulnerability
Record summary
CVE-2022-28700 has a selected CVSS score of 9.1 (critical).
Description
Authenticated Arbitrary File Creation via Export function vulnerability in GiveWP's GiveWP plugin <= 2.20.2 at WordPress.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Feb 20, 2025 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
GiveWP (WordPress plugin)Browse GiveWP / GiveWP (WordPress plugin) | CVE List | <= 2.20.2 to ≤ 2.20.2 | affected |
References
3patchstack.comConfirmation
https://patchstack.com/database/vulnerability/give/wordpress-givewp-plugin-2-20-2-authenticated-arbitrary-file-creation-via-export-function-vulnerability wordpress.orgConfirmation
https://wordpress.org/plugins/give