CVE-2019-20360
Last modified
CVE-2019-20360 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. A flaw in Give before 2.5.5, a WordPress plugin, allowed unauthenticated users to bypass API authentication methods and access personally identifiable user information (PII) including names, addresses, IP addresses, and email addresses. Once an API key has been set to any meta key value from the wp_usermeta table, and the token is set to the corresponding MD5 hash of the meta key selected, one can make a request to the restricted endpoints, and thus access sensitive donor data.. EPSS estimates a 2.46% chance of exploitation in the next 30 days.
Description
A flaw in Give before 2.5.5, a WordPress plugin, allowed unauthenticated users to bypass API authentication methods and access personally identifiable user information (PII) including names, addresses, IP addresses, and email addresses. Once an API key has been set to any meta key value from the wp_usermeta table, and the token is set to the corresponding MD5 hash of the meta key selected, one can make a request to the restricted endpoints, and thus access sensitive donor data.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Givewp | Givewp | < 2.5.5 |
References
- https://wpvulndb.com/vulnerabilities/9889Third Party Advisory
- https://www.wordfence.com/blog/2019/09/authentication-bypass-vulnerability-in-givewp-plugin/Exploit, Third Party Advisory
- https://wpvulndb.com/vulnerabilities/9889Third Party Advisory
- https://www.wordfence.com/blog/2019/09/authentication-bypass-vulnerability-in-givewp-plugin/Exploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2019-20360?
How severe is CVE-2019-20360?
How do I fix CVE-2019-20360?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2019
- CVE-2019-2035In rw_i93_sm_update_ndef of rw_i93.cc, there is a possible o…
- CVE-2019-20352In Netwide Assembler (NASM) 2.15rc0, a heap-based buffer ove…7.1
- CVE-2019-20354The web application component of piSignage before 2.6.4 allo…4.3
- CVE-2019-20357A Persistent Arbitrary Code Execution vulnerability exists i…7.8
- CVE-2019-20358Trend Micro Anti-Threat Toolkit (ATTK) versions 1.62.0.1218 …7.8
- CVE-2019-2036In okToConnect of HidHostService.java, there is a possible p…9.8
- CVE-2019-20361There was a flaw in the WordPress plugin, Email Subscribers …9.8
- CVE-2019-20362In Teradici PCoIP Agent before 19.08.1 and PCoIP Client befo…7.8
- CVE-2019-20363An XSS issue was discovered in Ignite Realtime Openfire 4.4.…6.1
- CVE-2019-20364An XSS issue was discovered in Ignite Realtime Openfire 4.4.…6.1
- CVE-2019-20365An XSS issue was discovered in Ignite Realtime Openfire 4.4.…6.1
- CVE-2019-20366An XSS issue was discovered in Ignite Realtime Openfire 4.4.…6.1
Are you affected by CVE-2019-20360?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
