CVE-2025-2331

CVSS 3.1 Score 5.3 of 10 (medium)

Details

Published Mar 22, 2025
CWE ID 200

Summary

CVE-2025-2331 is a vulnerability affecting the GiveWP plugin for WordPress, versions up to 3.22.1. This issue stems from a misconfigured capability check in the 'permissionsCheck' function, exposing sensitive information. Authenticated attackers with Subscriber-level access and above can exploit this vulnerability to extract reports detailing donors and their donation amounts, posing a significant risk to privacy.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share