Missing Authorization Vulnerability in GiveWP by Liquid Web
CVE-2023-23672
5.4MEDIUM
What is CVE-2023-23672?
A vulnerability exists in the GiveWP plugin, developed by Liquid Web, due to missing authorization checks. This flaw can potentially allow unauthorized users to perform actions that should be restricted, leading to unintended access to sensitive features or data within the plugin. Impacting versions up to 2.25.1, it poses significant risks for websites utilizing this popular WordPress solution. Proper mitigation strategies are essential to maintain the security integrity of affected sites.
Affected Version(s)
GiveWP <= 2.25.1