Dismissed
Permalink
CVE-2025-47444
7.5 HIGH
- CVSS version: 3.1
- Attack vector (AV): NETWORK
- Attack complexity (AC): LOW
- Privileges required (PR): NONE
- User interaction (UI): NONE
- Scope (S): UNCHANGED
- Confidentiality impact (C): HIGH
- Integrity impact (I): NONE
- Availability impact (A): NONE
by @LeSuisse Activity log
- Created automatic suggestion
- @LeSuisse removed package filegive
- @LeSuisse dismissed
WordPress GiveWP Plugin < 4.6.1 is vulnerable to Sensitive Data (PII) Exposure
Insertion of Sensitive Information Into Sent Data vulnerability in Liquid Web GiveWP allows Retrieve Embedded Sensitive Data.This issue affects GiveWP: from n/a before 4.6.1.
References
- https://patchstack.com/database/wordpress/plugin/give/vulnerability/wordpress-g… vdb-entry
- https://github.com/impress-org/givewp/issues/8042 issue-tracking technical-description
- https://patchstack.com/database/wordpress/plugin/give/vulnerability/wordpress-g… vdb-entry
- https://github.com/impress-org/givewp/issues/8042?_s_id=cve issue-tracking technical-description
Affected products
give
- <4.6.1