Insertion of Sensitive Information Into Sent Data vulnerability in Liquid Web GiveWP allows Retrieve Embedded Sensitive Data.This issue affects GiveWP: from n/a before 4.6.1.
Solution:
The code transmits data to another actor, but a portion of the data includes sensitive information that should not be accessible to that actor.
Link | Tags |
---|---|
https://patchstack.com/database/wordpress/plugin/give/vulnerability/wordpress-givewp-plugin-4-6-1-pii-sensitive-data-exposure-vulnerability | vdb entry |
https://github.com/impress-org/givewp/issues/8042 | issue tracking technical description |