GiveWP WordPress donation plugin flaw lets hackers execute server commands

Image: BleepingComputer
ad slot · in-content video 16:9
Coverage
Coverage
- A maximum-severity vulnerability in the GiveWP plugin for WordPress allows an unauthenticated attacker to execute arbitrary commands on the hosting server. [...]
More coverage
- Multiple critical security flaws have been disclosed in WordPress plugins and themes, including WPMU DEV Dashboard, Avada, TranslatePress, Pods, and GiveWP, that could lead to authentication bypass, account takeover, and arbitrary code execution. The vulnerabilities, according to Wordfence and…