GiveWP – Donation Plugin and Fundraising Platform, ddc4d6f1dffdee12cc66eecd059b50e53f3fa7b3
- CVE, Research URL
- Published on
- Mar 08, 2023
- Research Description
- GiveWP – Donation Plugin and Fundraising Platform [give] < 2.25.2 GiveWP <= 2.25.1 - Cross-Site Request Forgery to Cross-Site Scripting via render_dropdown The GiveWP plugin is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.25.1. This is due to missing or incorrect nonce validation on the 'render_dropdown' AJAX function. This makes it possible for unauthenticated attackers to execute JavaScript in the browser of an administrator via forged request granted a CSV file containing JavaScript in the column names has been uploaded and they can trick a site administrator into performing an action such as clicking on a link. Note that it is only possible to upload CSV files containing JavaScript tags in cases where ALLOW_UNFILTERED_UPLOADS is enabled.
- Affected versions
-
max 2.25.2.
- Status
-
vulnerable