CVE-2025-2331
CVSS 3.1 Score 5.3 of 10 (medium)
Details
Published Mar 22, 2025
CWE ID 200
Summary
CVE-2025-2331 is a vulnerability affecting the GiveWP plugin for WordPress, versions up to 3.22.1. This issue stems from a misconfigured capability check in the 'permissionsCheck' function, exposing sensitive information. Authenticated attackers with Subscriber-level access and above can exploit this vulnerability to extract reports detailing donors and their donation amounts, posing a significant risk to privacy.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- GiveWP Plugin
Affected Vendors
- WordPress