Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total26
Critical4
High2
Medium20
Reset
Showing 21-26 of 26 records
Threat Entry Updated 2024-11-21

CVE-2024-5977 - Give Plugin

The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.13.0 via the 'handleRequest' function due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with GiveWP Worker-level access and above, to delete and update arbitrary posts.

PLUGIN Give

CVE-2024-5977

MEDIUM CVSS 5.4 2024-07-19
Threat Entry Updated 2025-06-03

CVE-2023-4248 - Give Plugin

The GiveWP plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.33.3. This is due to missing or incorrect nonce validation on the give_stripe_disconnect_connect_stripe_account function. This makes it possible for unauthenticated attackers to deactivate the plugin's stripe integration settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Give

CVE-2023-4248

MEDIUM CVSS 5.4 2024-01-11
Threat Entry Updated 2024-11-21

CVE-2023-4247 - Give Plugin

The GiveWP plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.33.3. This is due to missing or incorrect nonce validation on the give_sendwp_disconnect function. This makes it possible for unauthenticated attackers to deactivate the SendWP plugin via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Give

CVE-2023-4247

MEDIUM CVSS 5.4 2024-01-11
Threat Entry Updated 2024-11-21

CVE-2023-4246 - Give Plugin

The GiveWP plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.33.3. This is due to missing or incorrect nonce validation on the give_sendwp_remote_install_handler function. This makes it possible for unauthenticated attackers to install and activate the SendWP plugin via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Give

CVE-2023-4246

MEDIUM CVSS 4.3 2024-01-11
Scroll to top