Description
WordPress Plugin GiveWP-Donation and Fundraising Platform is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently bypass API authentication methods and access personally identifiable user information. WordPress Plugin GiveWP-Donation and Fundraising Platform version 2.5.4 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 2.5.5 or latest
References
Related Vulnerabilities
TYPO3 Improper Input Validation Vulnerability (CVE-2013-7079)
WordPress Plugin Contest Gallery-Photo Contest for WordPress SQL Injection (13.1.0.5)
WordPress Plugin Redirection Multiple Cross-Site Scripting Vulnerabilities (2.2.11)
WordPress Permissions, Privileges, and Access Controls Vulnerability (CVE-2013-4340)