Tag: GiveWP WordPress donation plugin

Pi-hole discloses data breach triggered by WordPress plugin flaw
News

Pi-hole discloses data breach triggered by WordPress plugin flaw

A security flaw in the GiveWP WordPress donation plugin allowed donor names and email addresses to be accessed, according to Pi-hole, a well-known network-level ad-blocker. Pi-hole filters out undesirable content before it reaches consumers' devices by acting as a DNS sinkhole. Originally intended to run on Raspberry Pi single-board computers, it can now run a variety of Linux systems on virtual machines or dedicated hardware. After contributors started complaining that they were getting shady emails from addresses that were only used for donations, the organization said they first became aware of the situation on Monday, July 28. According to a Friday post-mortem, a GiveWP security weakness exposed personal information that was apparent to anybody viewing the webpage's source co...