The GiveWP WordPress plugin before 2.24.1 does not properly escape user input before it reaches SQL queries, which could let unauthenticated attackers perform SQL Injection attacks
History

Fri, 13 Jun 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published: 2024-01-16T15:54:45.597Z

Updated: 2025-06-13T16:07:48.744Z

Reserved: 2023-01-11T20:53:58.072Z

Link: CVE-2023-0224

cve-icon Vulnrichment

Updated: 2024-08-02T05:02:44.027Z

cve-icon NVD

Status : Modified

Published: 2024-01-16T16:15:10.440

Modified: 2025-06-13T16:15:24.050

Link: CVE-2023-0224

cve-icon Redhat

No data.