Privilege Escalation Vulnerability Affects GiveWP from n/a through 2.33.0
CVE-2023-41665

8.8HIGH

Key Information:

Vendor
GiveWP
Status
GiveWP
Vendor
CVE Published:
17 May 2024

Summary

An improper privilege management vulnerability exists in the GiveWP plugin that may allow attackers to escalate privileges within the application. This flaw could enable users with lower access permissions to gain higher privileges, potentially leading to unauthorized actions and compromise of sensitive data. The vulnerability affects GiveWP versions prior to 2.33.0, necessitating immediate updates and security measures to protect against potential exploitation.

Affected Version(s)

GiveWP <= 2.33.0

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Collectors

NVD DatabaseMitre Database

Credit

Rafie Muhammad (Patchstack)
.