Simple Giveaways <= 2.48.2 - Cross-Site Request Forgery
medium
The Simple Giveaways – Grow your business, email lists and traffic with contests plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.48.2. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to perf...
- CVSS:
- 4.3
- Affected:
- up to 2.48.2
- Fix:
- No patched version reported
- Disclosed:
- May 7, 2025
CVE-2025-47606 on NVD →
Simple Giveaways – Grow your business, email lists and traffic with contests [giveasap] <= 2.48.2 (unfixed)
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in Igor Benic Simple Giveaways allows Cross Site Request Forgery. This issue affects Simple Giveaways: from n/a through 2.48.2.
- Affected:
- up to 2.48.2
- Fix:
- No patched version reported
- Disclosed:
- May 7, 2025
CVE-2025-47606 on NVD →
Simple Giveaways <= 2.48.1 - Authenticated (Contributor+) SQL Injection
medium
The Simple Giveaways plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 2.48.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with contributor-level access a...
- CVSS:
- 6.5
- Affected:
- up to 2.48.1
- Fixed in:
- 2.48.2
- Disclosed:
- Mar 27, 2025
CVE-2025-30819 on NVD →
Simple Giveaways – Grow your business, email lists and traffic with contests [giveasap] < 2.48.2
unknown
[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Igor Benic Simple Giveaways allows SQL Injection. This issue affects Simple Giveaways: from n/a through 2.48.1.
- Affected:
- up to 2.48.2
- Fixed in:
- 2.48.2
- Disclosed:
- Mar 27, 2025
CVE-2025-30819 on NVD →
Simple Giveaways – Grow your business, email lists and traffic with contests [giveasap] < 2.46.1
unknown
[en] Missing Authorization vulnerability in Igor Benic Simple Giveaways allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Simple Giveaways: from n/a through 2.48.0.
- Affected:
- up to 2.46.1
- Fixed in:
- 2.46.1
- Disclosed:
- Dec 9, 2024
CVE-2023-23893 on NVD →
Simple Giveaways – Grow your business, email lists and traffic with contests [giveasap] < 2.42.1
unknown
[en] The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions in versions up to, and including 2.4....
- Affected:
- up to 2.42.1
- Fixed in:
- 2.42.1
- Disclosed:
- Oct 16, 2024
CVE-2022-4974 on NVD →
Simple Giveaways – Grow your business, email lists and traffic with contests [giveasap] < 2.46.1
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in Igor Benic Simple Giveaways – Grow your business, email lists and traffic with contests plugin <= 2.46.0 versions.
- Affected:
- up to 2.46.1
- Fixed in:
- 2.46.1
- Disclosed:
- Nov 9, 2023
CVE-2023-31086 on NVD →
Freemius SDK <= 2.5.9 - Reflected Cross-Site Scripting via fs_request_get
medium
The Freemius SDK for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘fs_request_get’ function in versions up to, and including, 2.5.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute...
- CVSS:
- 6.1
- Affected:
- up to 2.46.0
- Fixed in:
- 2.46.1
- Disclosed:
- Jul 18, 2023
CVE-2023-33999 on NVD →
Simple Giveaways <= 2.46.0 - Missing Authorization via AJAX actions
medium
The Simple Giveaways plugin for WordPress is vulnerable to unauthorized actions due to a missing capability check on several AJAX actions in versions up to, and including, 2.46.0. This makes it possible for unauthenticated attackers to perform unauthorized actions allowing them to see available giveaways, save plugin s...
- CVSS:
- 6.5
- Affected:
- up to 2.46.0
- Fixed in:
- 2.46.1
- Disclosed:
- Jul 4, 2023
CVE-2023-23893 on NVD →
Simple Giveaways <= 2.46 - Cross-Site Request Forgery
medium
The Simple Giveaways plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.46. This is due to missing or incorrect nonce validation on multiple functions. This makes it possible for unauthenticated attackers to save plugin settings, end giveaways and select winners among o...
- CVSS:
- 5.4
- Affected:
- up to 2.46
- Fixed in:
- 2.46.1
- Disclosed:
- Apr 24, 2023
CVE-2023-31086 on NVD →
Simple Giveaways – Grow your business, email lists and traffic with contests [giveasap] < 2.45.1
unknown
[en] The Simple Giveaways WordPress plugin before 2.45.1 does not sanitise and escape some of its Giveaways options, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
- Affected:
- up to 2.45.1
- Fixed in:
- 2.45.1
- Disclosed:
- Apr 10, 2023
CVE-2023-1122 on NVD →
Simple Giveaways – Grow your business, email lists and traffic with contests [giveasap] < 2.45.1
unknown
[en] The Simple Giveaways WordPress plugin before 2.45.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
- Affected:
- up to 2.45.1
- Fixed in:
- 2.45.1
- Disclosed:
- Apr 10, 2023
CVE-2023-1121 on NVD →
Simple Giveaways – Grow your business, email lists and traffic with contests [giveasap] < 2.45.1
unknown
[en] The Simple Giveaways WordPress plugin before 2.45.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
- Affected:
- up to 2.45.1
- Fixed in:
- 2.45.1
- Disclosed:
- Apr 10, 2023
CVE-2023-1120 on NVD →
Simple Giveaways <= 2.45.0 - Authenticated (Editor+) Stored Cross-Site Scripting via Form, Prize, and Sharing Method Fields
medium
The Simple Giveaways plugin for WordPress is vulnerable to Stored Cross-Site Scripting via certain form, prize, and sharing method fields in versions up to, and including, 2.45.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with editor-level permissions...
- CVSS:
- 5.5
- Affected:
- up to 2.45.0
- Fixed in:
- 2.45.1
- Disclosed:
- Mar 20, 2023
CVE-2023-1122 on NVD →
Simple Giveaways <= 2.45.0 - Authenticated(Admin+) Stored Cross-Site Scripting via form fields
medium
The Simple Giveaways plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple form fields in versions up to, and including, 2.45.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inj...
- CVSS:
- 4.4
- Affected:
- up to 2.45.0
- Fixed in:
- 2.45.1
- Disclosed:
- Mar 20, 2023
CVE-2023-1121 on NVD →
Simple Giveaways <= 2.45.0 - Authenticated (Admin+) Stored Cross-Site Scripting via Settings
medium
The Simple Giveaways plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 2.45.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arb...
- CVSS:
- 4.4
- Affected:
- up to 2.45.0
- Fixed in:
- 2.45.1
- Disclosed:
- Mar 20, 2023
CVE-2023-1120 on NVD →
Freemius SDK <= 2.4.2 - Missing Authorization Checks
medium
The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions in versions up to, and including 2.4.2. An...
- CVSS:
- 6.3
- Affected:
- up to 2.42.1
- Fixed in:
- 2.42.1
- Disclosed:
- Mar 4, 2022
CVE-2022-4974 on NVD →
Simple Giveaways – Grow your business, email lists and traffic with contests [giveasap] < 2.42.1
unknown
The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions in versions up to, and including 2.4.2. An...
- Affected:
- up to 2.42.1
- Fixed in:
- 2.42.1
- Disclosed:
- Mar 4, 2022
Simple Giveaways – Grow your business, email lists and traffic with contests [giveasap] < 2.42.1
unknown
Sensitive Information Disclosure vulnerability discovered in WordPress Simple Giveaways plugin (versions <= 2.42.0).
- Affected:
- up to 2.42.1
- Fixed in:
- 2.42.1
- Disclosed:
- Feb 28, 2022
Simple Giveaways – Grow your business, email lists and traffic with contests [giveasap] < 2.42.1
unknown
Toggle The Debug Mode via Cross-Site Request Forgery (CSRF) vulnerability discovered in WordPress Simple Giveaways plugin (versions <= 2.42.0).
- Affected:
- up to 2.42.1
- Fixed in:
- 2.42.1
- Disclosed:
- Feb 28, 2022
Simple Giveaways – Grow your business, email lists and traffic with contests [giveasap] < 2.36.2
unknown
[en] The method and share GET parameters of the Giveaway pages were not sanitised, validated or escaped before being output back in the pages, thus leading to reflected XSS
- Affected:
- up to 2.36.2
- Fixed in:
- 2.36.2
- Disclosed:
- May 24, 2021
CVE-2021-24298 on NVD →
Simple Giveaways <= 2.36.1 - Reflected Cross-Site Scripting
medium
The Simple Giveaways for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'method' and 'share' parameters in versions up to, and including, 2.36.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages th...
- CVSS:
- 6.1
- Affected:
- up to 2.36.1
- Fixed in:
- 2.36.2
- Disclosed:
- May 9, 2021
CVE-2021-24298 on NVD →
Freemius SDK <= 2.2.3 - Missing Authorization to Arbitrary Options Update
high
The Freemius SDK for WordPress is vulnerable to authorization bypass due to a missing capability check on the _get_db_option and _set_db_option functions in versions up to, and including, 2.2.3. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to change site settings and...
- CVSS:
- 8.8
- Affected:
- up to 2.18.0
- Fixed in:
- 2.18.0
- Disclosed:
- Feb 25, 2019
Simple Giveaways – Grow your business, email lists and traffic with contests [giveasap] < 2.18.0
unknown
The Freemius SDK for WordPress is vulnerable to authorization bypass due to a missing capability check on the _get_db_option and _set_db_option functions in versions up to, and including, 2.2.3. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to change site settings and...
- Affected:
- up to 2.18.0
- Fixed in:
- 2.18.0
- Disclosed:
- Feb 25, 2019
Simple Giveaways – Grow your business, email lists and traffic with contests [giveasap] < 2.18.0
unknown
The library, used in numerous plugins, does not have proper authorisation when updating blog options, allowing any authenticated users, such as subscriber to update arbitrary options
- Affected:
- up to 2.18.0
- Fixed in:
- 2.18.0
Simple Giveaways – Grow your business, email lists and traffic with contests [giveasap] < 2.46.1
unknown
** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.
- Affected:
- up to 2.46.1
- Fixed in:
- 2.46.1
CVE-2023-33999 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database