cleantalk
Vulnerabilities and Security Researches

GiveWP – Donation Plugin and Fundraising Platform, 18581ce2a41a83577c47ee957da977cb59a69edc

Published on
Mar 08, 2023
Research Description
GiveWP &#8211; Donation Plugin and Fundraising Platform [give] < 2.25.2 GiveWP <= 2.25.1 - Authenticated (Admin+) Server-Side Request Forgery via give_get_content_by_ajax_handler The GiveWP plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including, 2.25.1 via the 'give_get_content_by_ajax_handler'. This can allow authenticated attackers with administrator-level privileges to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services.
Affected versions
max 2.25.2.
Status
vulnerable