The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.13.0 via the 'handleRequest' function due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with GiveWP Worker-level access and above, to delete and update arbitrary posts.
We have discovered 11,415 live websites that are affected by CVE-2024-5977.
Product | |
Category | Wordpress Plugins |
Vulnerable Domains | 11,415 live websites (31.31% of GiveWP install base) |
Vulnerable Versions |
|
Vulnerable Versions Count | 209 versions ( 88.19% of all versions) |
![]() | 5,282 websites |
![]() | 1,238 websites |
![]() | 683 websites |
![]() | 591 websites |
![]() | 333 websites |
![]() | 310 websites |
![]() | 242 websites |
![]() | 198 websites |
![]() | 181 websites |
![]() | 152 websites |
.org | 4,506 websites |
.com | 2,878 websites |
.de | 313 websites |
.it | 252 websites |
.net | 196 websites |
.fr | 195 websites |
.ca | 189 websites |
.org.uk | 188 websites |
.co.uk | 161 websites |
.nl | 103 websites |
Domain | Country | Rank | Contacts |
---|---|---|---|
*************.sk | ![]() | **,*** | |
********.org | ![]() | **,*** | |
*********.org | ![]() | **,*** | |
************.org | ![]() | **,*** | |
****************.org | ![]() | **,*** | |
*******.org | ![]() | **,*** | |
**************.com | ![]() | **,*** | |
****.org | ![]() | **,*** | |
**********.net | ![]() | ***,*** | |
***.***.uk | ![]() | ***,*** |
FAQ