
CVE-2022-28700 – WordPress GiveWP plugin <= 2.20.2 - Authenticated Arbitrary File Creation via Export function vulnerability
https://notcve.org/view.php?id=CVE-2022-28700
12 Jul 2022 — Authenticated Arbitrary File Creation via Export function vulnerability in GiveWP's GiveWP plugin <= 2.20.2 at WordPress. Una vulnerabilidad de creación de archivos arbitrarios autenticados por medio de la función Export en el plugin GiveWP de GiveWP versiones anteriores a 2.20.2 incluyéndola, en WordPress • https://patchstack.com/database/vulnerability/give/wordpress-givewp-plugin-2-20-2-authenticated-arbitrary-file-creation-via-export-function-vulnerability • CWE-285: Improper Authorization CWE-434: Unrestricted Upload of File with Dangerous Type •

CVE-2022-2215 – GiveWP < 2.21.3 - Admin+ Stored Cross-Site Scripting
https://notcve.org/view.php?id=CVE-2022-2215
11 Jul 2022 — The GiveWP WordPress plugin before 2.21.3 does not properly sanitise and escape the currency settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks when the unfiltered_html capability is disallowed (for example in multisite setup) El plugin GiveWP de WordPress versiones anteriores a 2.21.3, no sanea ni escapa apropiadamente de la configuración de la moneda, lo que podría permitir a usuarios con altos privilegios, como los administradores, llevar a cabo ... • https://wpscan.com/vulnerability/daa9b6c1-1ee1-434c-9f88-fd273b7e20bb • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2022-2260 – GiveWP < 2.21.3 - DoS via CSRF
https://notcve.org/view.php?id=CVE-2022-2260
08 Jul 2022 — The GiveWP WordPress plugin before 2.21.3 does not have CSRF in place when exporting data, and does not validate the exporting parameters such as dates, which could allow attackers to make a logged in admin DoS the web server via a CSRF attack as the plugin will try to retrieve data from the database many times which leads to overwhelm the target's CPU. El plugin GiveWP de WordPress versiones anteriores a 2.21.3, no presenta comprobación de tipo CSRF cuando exporta datos, y no comprueba los parámetros de ex... • https://wpscan.com/vulnerability/831b3afa-8fa3-4cb7-8374-36d0c368292f • CWE-352: Cross-Site Request Forgery (CSRF) •

CVE-2022-2117 – GiveWP – Donation Plugin and Fundraising Platform <= 2.20.2 - Sensitive Information Disclosure
https://notcve.org/view.php?id=CVE-2022-2117
17 Jun 2022 — The GiveWP plugin for WordPress is vulnerable to Sensitive Information Disclosure in versions up to, and including, 2.20.2 via the /donor-wall REST-API endpoint which provides unauthenticated users with donor information even when the donor wall is not enabled. This functionality has been completely removed in version 2.20.2. El plugin GiveWP para WordPress es vulnerable a la divulgación de información confidencial en versiones hasta 2.20.2 incluyéndola, por medio del endpoint /donor-wall REST-API que propo... • https://plugins.trac.wordpress.org/changeset/2743833/give/tags/2.21.0/includes/api/class-give-api-v2.php • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVE-2021-25099 – Give < 2.17.3 - Unauthenticated Reflected Cross-Site Scripting
https://notcve.org/view.php?id=CVE-2021-25099
18 Jan 2022 — The GiveWP WordPress plugin before 2.17.3 does not sanitise and escape the form_id parameter before outputting it back in the response of an unauthenticated request via the give_checkout_login AJAX action, leading to a Reflected Cross-Site Scripting El plugin GiveWP de WordPress versiones anteriores a 2.17.3, no sanea y escapa del parámetro form_id antes de devolverlo en la respuesta de una petición no autenticada por medio de la acción give_checkout_login AJAX, conllevando a un problema de tipo Cross-Site ... • https://plugins.trac.wordpress.org/changeset/2659032 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2021-25100 – Give < 2.17.3 - Reflected Cross-Site Scripting via Donation Forms Dashboard
https://notcve.org/view.php?id=CVE-2021-25100
18 Jan 2022 — The GiveWP WordPress plugin before 2.17.3 does not escape the s parameter before outputting it back in an attribute in the Donation Forms dashboard, leading to a Reflected Cross-Site Scripting El plugin GiveWP de WordPress versiones anteriores a 2.17.3, no escapa el parámetro s antes de devolverlo en un atributo en el panel de formularios de donación, conllevando a un problema de tipo Cross-Site Scripting Reflejado • https://plugins.trac.wordpress.org/changeset/2659032 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2022-0252 – Give < 2.17.3 - Reflected Cross-Site Scripting via Import Tool
https://notcve.org/view.php?id=CVE-2022-0252
18 Jan 2022 — The GiveWP WordPress plugin before 2.17.3 does not escape the json parameter before outputting it back in an attribute in the Import admin dashboard, leading to a Reflected Cross-Site Scripting El plugin GiveWP de WordPress versiones anteriores a 2.17.3, no escapa del parámetro json antes de devolverlo en un atributo en el panel de administración de importación, conllevando a un problema de tipo Cross-Site Scripting Reflejado • https://plugins.trac.wordpress.org/changeset/2659032 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2021-24524 – GiveWP < 2.12.0 - Authenticated Stored XSS
https://notcve.org/view.php?id=CVE-2021-24524
26 Jul 2021 — The GiveWP – Donation Plugin and Fundraising Platform WordPress plugin before 2.12.0 did not escape the Donation Level setting of its Donation Forms, allowing high privilege users to use Cross-Site Scripting payloads in them. El plugin GiveWP - Donation Plugin and Fundraising Platform WordPress versiones anteriores a 2.12.0, no escapaba la configuración del Nivel de Donación de sus Formularios de Donación, permitiendo a usuarios con altos privilegios usar cargas útiles de tipo Cross-Site Scripting en ellos. • https://wpscan.com/vulnerability/5a4774ec-c0ee-4c6b-92a6-fa10821ec336 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2021-24315 – Give WP < 2.10.4 - Authenticated Stored Cross-Site Scripting (XSS)
https://notcve.org/view.php?id=CVE-2021-24315
30 Apr 2021 — The GiveWP – Donation Plugin and Fundraising Platform WordPress plugin before 2.10.4 did not sanitise or escape the Background Image field of its Stripe Checkout Setting and Logo field in its Email settings, leading to authenticated (admin+) Stored XSS issues. El plugin de WordPress GiveWP – Donation Plugin and Fundraising Platform versiones anteriores a 2.10.4, no sanea ni escapa del campo Background Image de su Stripe Checkout Setting y el campo Logo en su configuración de correo electrónico, conllevand... • https://m0ze.ru/vulnerability/%5B2021-04-02%5D-%5BWordPress%5D-%5BCWE-79%5D-GiveWP-WordPress-Plugin-v2.10.3.txt • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2021-24213 – GiveWP < 2.10.0 - Reflected Cross Site Scripting (XSS)
https://notcve.org/view.php?id=CVE-2021-24213
23 Mar 2021 — The GiveWP – Donation Plugin and Fundraising Platform WordPress plugin before 2.10.0 was affected by a reflected Cross-Site Scripting vulnerability inside of the administration panel, via the 's' GET parameter on the Donors page. El plugin GiveWP - Donation Plugin and Fundraising Platform WordPress versiones anteriores a 2.10.0, estuvo afectado por una vulnerabilidad de tipo Cross-Site Scripting reflejado dentro del panel de administración, por medio del parámetro GET "s" en la página Donors WordPress GiveW... • https://packetstorm.news/files/id/161933 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •