The GiveWP plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.33.3. This is due to missing or incorrect nonce validation on the give_stripe_disconnect_connect_stripe_account function. This makes it possible for unauthenticated attackers to deactivate the plugin's stripe integration settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
We have discovered 7,643 live websites that are affected by CVE-2023-4248.
Product | |
Category | Wordpress Plugins |
Vulnerable Domains | 7,643 live websites (20.96% of GiveWP install base) |
Vulnerable Versions |
|
Vulnerable Versions Count | 178 versions ( 75.11% of all versions) |
![]() | 3,545 websites |
![]() | 810 websites |
![]() | 477 websites |
![]() | 390 websites |
![]() | 224 websites |
![]() | 171 websites |
![]() | 164 websites |
![]() | 133 websites |
![]() | 116 websites |
![]() | 108 websites |
.org | 2,952 websites |
.com | 1,969 websites |
.de | 203 websites |
.it | 179 websites |
.fr | 138 websites |
.net | 135 websites |
.ca | 131 websites |
.org.uk | 126 websites |
.co.uk | 108 websites |
.pl | 72 websites |
Domain | Country | Rank | Contacts |
---|---|---|---|
*************.sk | ![]() | **,*** | |
********.org | ![]() | **,*** | |
*********.org | ![]() | **,*** | |
****************.org | ![]() | **,*** | |
*******.org | ![]() | **,*** | |
**************.com | ![]() | **,*** | |
****.org | ![]() | **,*** | |
**********.net | ![]() | ***,*** | |
***.***.uk | ![]() | ***,*** | |
****************.org | ![]() | ***,*** |