CVE-2020-20627

Severity CVSS v4.0:
Pending analysis
Type:
CWE-306 Missing Authentication for Critical Function
Publication date:
31/08/2020
Last modified:
06/02/2023

Description

The includes/gateways/stripe/includes/admin/admin-actions.php in GiveWP plugin through 2.5.9 for WordPress allows unauthenticated settings change.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:givewp:givewp:*:*:*:*:*:wordpress:*:* 2.5.9 (including)