Pi-hole discloses data breach triggered by WordPress plugin flaw

Pi-hole discloses data breach triggered by WordPress plugin flaw

Pi-hole experienced a data breach exposing donor names and email addresses due to a vulnerability in the GiveWP WordPress plugin. Almost 30,000 donors were affected, but no financial information was compromised. #GiveWP #Pi-hole #DataBreach

Keypoints

  • Pi-hole disclosed a security vulnerability involving the GiveWP donation plugin that exposed donor information.
  • The breach affected nearly 30,000 donors, with personal data visible through webpage source code.
  • GiveWP’s delayed notification and inadequate response drew criticism from Pi-hole.
  • No financial or payment data was compromised, as those are securely handled by Stripe and PayPal.
  • Pi-hole clarified that its core software was unaffected and no action is required from users.

Read More: https://www.bleepingcomputer.com/news/security/pi-hole-discloses-data-breach-via-givewp-wordpress-plugin-flaw/