cleantalk
Vulnerabilities and Security Researches

GiveWP – Donation Plugin and Fundraising Platform, bdd35f9578d2dbb911216645154f659f6cbd203f

Published on
Aug 31, 2023
Research Description
GiveWP &#8211; Donation Plugin and Fundraising Platform [give] < 2.33.1 Give - Donation Plugin <= 2.33.0 - Authenticated(Give Manager+) Privilege Escalation The Give - Donation Plugin plugin for WordPress is vulnerable to privilege escalation due to an insufficient capability check when updating default roles in versions up to, and including, 2.33.0. This makes it possible for authenticated attackers with Give Manager privileges to elevate their privileges to those of an administrator by setting the default role in the plugin's settings.
Affected versions
max 2.33.1.
Status
vulnerable