The includes/gateways/stripe/includes/admin/admin-actions.php in GiveWP plugin through 2.5.9 for WordPress allows unauthenticated settings change.
Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-20627
Reference (s):
- https://blog.nintechnet.com/multiple-vulnerabilities-fixed-in-wordpress-givewp-plugin/

