Sensitive Information Exposure in Give – Divi Donation Modules by Matt Cromwell
CVE-2025-22633

5.8MEDIUM

Key Information:

Vendor
Matt Cromwell
Status
Give – Divi Donation Modules
Vendor
CVE Published:
23 February 2025

Summary

A vulnerability exists within the Give – Divi Donation Modules by Matt Cromwell that enables the unwanted exposure of sensitive data through an externally-accessible file or directory. This flaw could allow attackers to retrieve embedded sensitive information, potentially compromising the confidentiality of user data. The issue has been identified in versions from n/a up to 2.0.0, highlighting the need for users to address this vulnerability promptly to safeguard their WordPress installations.

Affected Version(s)

Give – Divi Donation Modules <= 2.0.0

References

CVSS V3.1

Score:
5.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Anhchangmutrang (Patchstack Alliance)
.