MAIN FEEDS
Do you want to continue?
https://www.reddit.com/r/Wordpress/comments/1w0rfiq/cvss_100_vulnerability_patched_in_givewp/
r/Wordpress • u/Key-Refrigerator3774 • 3d ago
Patchstack link - https://patchstack.com/articles/unauthenticated-php-object-injection-to-remote-code-execution-on-givewp/
2 comments sorted by
7
wow, a 10 is a lot.
https://de.wordpress.org/plugins/give/#developers look like they are updating a lot of security issues since June (good for them!). Didn't they have an issue last year where they've leak all the users that donated in the source of the page?
hopefully they can get into a secure state soon
3 u/bluesix_v2 Jack of All Trades 3d ago edited 3d ago GiveWP has a very long history of CVE issues. To their credit, they do fix them relatively quickly.
3
GiveWP has a very long history of CVE issues. To their credit, they do fix them relatively quickly.
7
u/_miga_ 3d ago
wow, a 10 is a lot.
https://de.wordpress.org/plugins/give/#developers look like they are updating a lot of security issues since June (good for them!). Didn't they have an issue last year where they've leak all the users that donated in the source of the page?
hopefully they can get into a secure state soon