Cross-Site Request Forgery Vulnerability in StellarWP GiveWP Plugin
CVE-2025-67467
4.5MEDIUM
What is CVE-2025-67467?
A Cross-Site Request Forgery (CSRF) vulnerability exists in the StellarWP GiveWP plugin, which could allow an attacker to perform unauthorized actions on behalf of users without their consent. This issue affects all versions from n/a up to and including 4.13.1, posing a significant risk to user data and web application integrity. Website administrators are encouraged to implement the latest security updates to mitigate this risk.
Affected Version(s)
GiveWP <= n/a
References
CVSS V3.1
Score:
4.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
mcdruid | Patchstack Bug Bounty Program