Vulnerabilities and security researches forgiveasap giveasap
Direction: ascendingJun 07, 2024
Simple Giveaways – Grow your business, email lists and traffic with contests # CVE-2021-24298
- CVE, Research URL
- Home page URL
- Date
- May 24, 2021
- Research Description
- The method and share GET parameters of the Giveaway pages were not sanitised, validated or escaped before being output back in the pages, thus leading to reflected XSS
- Affected versions
-
max 2.36.2.
- Status
-
vulnerable
Simple Giveaways – Grow your business, email lists and traffic with contests # CVE-2023-1121
- CVE, Research URL
- Home page URL
- Date
- Apr 10, 2023
- Research Description
- The Simple Giveaways WordPress plugin before 2.45.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
- Affected versions
-
max 2.45.1.
- Status
-
vulnerable
Simple Giveaways – Grow your business, email lists and traffic with contests # CVE-2023-1122
- CVE, Research URL
- Home page URL
- Date
- Apr 10, 2023
- Research Description
- The Simple Giveaways WordPress plugin before 2.45.1 does not sanitise and escape some of its Giveaways options, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
- Affected versions
-
max 2.45.1.
- Status
-
vulnerable
Simple Giveaways – Grow your business, email lists and traffic with contests # CVE-2023-31086
- CVE, Research URL
- Home page URL
- Date
- Nov 10, 2023
- Research Description
- Cross-Site Request Forgery (CSRF) vulnerability in Igor Benic Simple Giveaways – Grow your business, email lists and traffic with contests plugin <= 2.46.0 versions.
- Affected versions
-
max 2.46.1.
- Status
-
vulnerable
Simple Giveaways – Grow your business, email lists and traffic with contests # CVE-2023-1120
- CVE, Research URL
- Home page URL
- Date
- Apr 10, 2023
- Research Description
- The Simple Giveaways WordPress plugin before 2.45.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
- Affected versions
-
max 2.45.1.
- Status
-
vulnerable
Jun 10, 2024
Simple Giveaways – Grow your business, email lists and traffic with contests # CVE-2023-23893
- CVE, Research URL
- Home page URL
- Date
- Dec 09, 2024
- Research Description
- Missing Authorization vulnerability in Igor Benic Simple Giveaways allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Simple Giveaways: from n/a through 2.48.0.
- Affected versions
-
max 2.46.1.
- Status
-
vulnerable
Nov 15, 2024
Simple Giveaways – Grow your business, email lists and traffic with contests # CVE-2022-4974
- CVE, Research URL
- Home page URL
- Date
- Oct 16, 2024
- Research Description
- The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions in versions up to, and including 2.4.2. Any WordPress plugin or theme running a version of Freemius less than 2.4.3 is vulnerable.
- Affected versions
-
max 2.42.1.
- Status
-
vulnerable
Apr 02, 2025
Simple Giveaways – Grow your business, email lists and traffic with contests # CVE-2025-30819
- CVE, Research URL
- Home page URL
- Date
- Mar 27, 2025
- Research Description
- Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Igor Benic Simple Giveaways giveasap allows SQL Injection.This issue affects Simple Giveaways: from n/a through <= 2.48.1.
- Affected versions
-
max 2.48.2.
- Status
-
vulnerable
May 09, 2025
Simple Giveaways – Grow your business, email lists and traffic with contests # CVE-2025-47606
- CVE, Research URL
- Home page URL
- Date
- May 07, 2025
- Research Description
- Cross-Site Request Forgery (CSRF) vulnerability in Igor Benic Simple Giveaways giveasap allows Cross Site Request Forgery.This issue affects Simple Giveaways: from n/a through <= 2.49.0.
- Affected versions
-
max 2.49.0.
- Status
-
vulnerable
Jun 16, 2026
Simple Giveaways – Grow your business, email lists and traffic with contests # e26d807e4bbbff14166bf152a0dee6e17c165896
- CVE, Research URL
- Home page URL
- Date
- Feb 28, 2022
- Research Description
- Simple Giveaways – Grow your business, email lists and traffic with contests [giveasap] < 2.42.1 WordPress Simple Giveaways plugin <= 2.42.0 - Sensitive Information Disclosure vulnerability Sensitive Information Disclosure vulnerability discovered in WordPress Simple Giveaways plugin (versions <= 2.42.0).
- Affected versions
-
max 2.42.1.
- Status
-
vulnerable
Simple Giveaways – Grow your business, email lists and traffic with contests # f3cae5511738475f4103ff8af0be631163f4af46
- CVE, Research URL
- Home page URL
- Date
- Feb 28, 2022
- Research Description
- Simple Giveaways – Grow your business, email lists and traffic with contests [giveasap] < 2.42.1 WordPress Simple Giveaways plugin <= 2.42.0 - Toggle The Debug Mode via Cross-Site Request Forgery (CSRF) vulnerability Toggle The Debug Mode via Cross-Site Request Forgery (CSRF) vulnerability discovered in WordPress Simple Giveaways plugin (versions <= 2.42.0).
- Affected versions
-
max 2.42.1.
- Status
-
vulnerable
Simple Giveaways – Grow your business, email lists and traffic with contests # 6ff37c2e-e21d-4abc-bafe-8ca6a2c1ed76
- CVE, Research URL
- Home page URL
- Date
- -
- Research Description
- Simple Giveaways – Grow your business, email lists and traffic with contests [giveasap] < 2.18.0 Freemius Library < 2.2.4 - Subscriber+ Arbitrary Option Update The library, used in numerous plugins, does not have proper authorisation when updating blog options, allowing any authenticated users, such as subscriber to update arbitrary options
- Affected versions
-
max 2.18.0.
- Status
-
vulnerable
Simple Giveaways – Grow your business, email lists and traffic with contests # 7e57cd4f4859826de00a8e2b09ee24fb7f2d824b
- CVE, Research URL
- Home page URL
- Date
- Feb 25, 2019
- Research Description
- Simple Giveaways – Grow your business, email lists and traffic with contests [giveasap] < 2.18.0 Freemius SDK <= 2.2.3 - Missing Authorization to Arbitrary Options Update The Freemius SDK for WordPress is vulnerable to authorization bypass due to a missing capability check on the _get_db_option and _set_db_option functions in versions up to, and including, 2.2.3. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to change site settings and potentially take over the site.
- Affected versions
-
max 2.18.0.
- Status
-
vulnerable
Simple Giveaways – Grow your business, email lists and traffic with contests # 6d8910c719b2a132ec93828cd37e418b19cac960
- CVE, Research URL
- Home page URL
- Date
- Mar 04, 2022
- Research Description
- Simple Giveaways – Grow your business, email lists and traffic with contests [giveasap] < 2.42.1 Freemius SDK <= 2.4.2 - Missing Authorization Checks The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions in versions up to, and including 2.4.2. Any WordPress plugin or theme running a version of Freemius less than 2.4.3 is vulnerable.
- Affected versions
-
max 2.42.1.
- Status
-
vulnerable