CVE-2024-5977

GiveWP – Donation Plugin and Fundraising Platform <= 3.13.0 - Insecure Direct Object Reference to Authenticated (GiveWP Worker+) Arbitrary Post Actions

The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.13.0 via the 'handleRequest' function due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with GiveWP Worker-level access and above, to delete and update arbitrary posts.


We have discovered 11,415 live websites that are affected by CVE-2024-5977.

Test my site




Affected Software

Product  GiveWP
Category Wordpress Plugins
Vulnerable Domains11,415 live websites (31.31% of GiveWP install base)
Vulnerable Versions
  • from 0 through 3.13
Vulnerable Versions Count209 versions ( 88.19% of all versions)


Common Weakness Enumeration

CWE-639 Authorization Bypass Through User-Controlled Key



Details

  • Published - Jul 19, 2024
  • Updated - Aug 1, 2024

Credits

  • Thanh Nam Tran (finder)

CVE-2024-5977 usage by Country

United States5,282 websites



Germany1,238 websites
France683 websites
GB591 websites
Cyprus333 websites
Italy310 websites
Canada242 websites
Australia198 websites
Spain181 websites
South Africa152 websites

CVE-2024-5977 usage by TLD

.org4,506 websites
.com2,878 websites
.de313 websites
.it252 websites
.net196 websites
.fr195 websites
.ca189 websites
.org.uk188 websites
.co.uk161 websites
.nl103 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2024-5977

Top websites that are affected by CVE-2024-5977. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*************.sk United States**,***
********.org United States**,***
*********.org United States**,***
************.org United States**,***
****************.org Germany**,***
*******.org United States**,***
**************.com Australia**,***
****.org United States**,***
**********.net United States***,***
***.***.uk United States***,***
See full domain list

FAQ

CVE-2024-5977 is Authorization Bypass Through User-Controlled Key in GiveWP
A total of 11,415 websites have been identified as vulnerable to CVE-2024-5977, discovered through global website indexing conducted by WebTechSurvey.
GiveWP is susceptible to CVE-2024-5977 vulnerability.
GiveWP versions before, and including, 3.13 are vulnerable to CVE-2024-5977.