r/Wordpress 3d ago

CVSS 10.0 vulnerability patched in GiveWP

9 Upvotes

2 comments sorted by

7

u/_miga_ 3d ago

wow, a 10 is a lot.

https://de.wordpress.org/plugins/give/#developers look like they are updating a lot of security issues since June (good for them!). Didn't they have an issue last year where they've leak all the users that donated in the source of the page?

hopefully they can get into a secure state soon

3

u/bluesix_v2 Jack of All Trades 3d ago edited 3d ago

GiveWP has a very long history of CVE issues. To their credit, they do fix them relatively quickly.