cleantalk

Vulnerabilities and Security Researches

Security report for CVE GiveWP – Donation Plugin and Fundraising Platform > CVE-2022-2215

CVE, Research URL

CVE-2022-2215

Published on
Aug 01, 2022
Research Description
The GiveWP WordPress plugin before 2.21.3 does not properly sanitise and escape the currency settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks when the unfiltered_html capability is disallowed (for example in multisite setup)
Affected versions
Min -, max 0.8.5.
Status
vulnerable