Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-2331

Опубликовано: 22 мар. 2025
Источник: nvd
CVSS3: 5.3
CVSS3: 6.5
EPSS Низкий

Описание

The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.22.1 via a misconfigured capability check in the 'permissionsCheck' function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to extract sensitive data including reports detailing donors and donation amounts.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:givewp:givewp:*:*:*:*:*:wordpress:*:*
Версия до 3.22.2 (исключая)

EPSS

Процентиль: 35%
0.00145
Низкий

5.3 Medium

CVSS3

6.5 Medium

CVSS3

Дефекты

CWE-200
NVD-CWE-noinfo

Связанные уязвимости

CVSS3: 5.3
github
11 месяцев назад

The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.22.1 via a misconfigured capability check in the 'permissionsCheck' function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to extract sensitive data including reports detailing donors and donation amounts.

EPSS

Процентиль: 35%
0.00145
Низкий

5.3 Medium

CVSS3

6.5 Medium

CVSS3

Дефекты

CWE-200
NVD-CWE-noinfo