← Back to browse · API

CVE-2023-0224

Severity
CRITICAL
CVSS
9.8
EPSS
0.03742
Risk score
40.51
CISA KEV
No
PoC
No
Published
2024-01-16
Modified
2025-06-13
First seen
2026-08-07
Aliases
EUVD-2023-12310, GHSA-6737-MXC9-2P4P
Products
StellarWP:GiveWP 0 <2.24.1
Sources
euvd EUVD-2023-12310

Description

The GiveWP WordPress plugin before 2.24.1 does not properly escape user input before it reaches SQL queries, which could let unauthenticated attackers perform SQL Injection attacks

References