nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2022-40312 CVE-2022-40312
MEDIUM
WordPress GiveWP Plugin <= 2.25.1 is vulnerable to Server Side Request Forgery (SSRF)
Record summary
CVE-2022-40312 has a selected CVSS score of 5.5 (medium).
Description
Server-Side Request Forgery (SSRF) vulnerability in GiveWP GiveWP – Donation Plugin and Fundraising Platform.This issue affects GiveWP – Donation Plugin and Fundraising Platform: from n/a through 2.25.1.
Description source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
GiveWP – Donation Plugin and Fundraising PlatformBrowse GiveWP / GiveWP – Donation Plugin and Fundraising PlatformgiveDefault status: unaffected | CVE List | Through 2.25.1 | affected |
References
2patchstack.comvdb entry
https://patchstack.com/database/vulnerability/give/wordpress-givewp-plugin-2-25-1-server-side-request-forgery-ssrf-vulnerability?_s_id=cve