{"id":7835,"date":"2025-08-07T19:26:36","date_gmt":"2025-08-07T17:26:36","guid":{"rendered":"https:\/\/www.lrob.fr\/?p=7835"},"modified":"2025-08-07T19:26:36","modified_gmt":"2025-08-07T17:26:36","slug":"fuite-de-donnees-givewp-100-000-sites-wordpress","status":"publish","type":"post","link":"https:\/\/portail.lrob.fr\/en\/securite\/fuite-de-donnees-givewp-100-000-sites-wordpress\/","title":{"rendered":"\ud83d\udca5 Fuite de donn\u00e9es sur GiveWP : plus de 100 000 sites WordPress concern\u00e9s"},"content":{"rendered":"<h2 class=\"wp-block-heading\" id=\"une-faille-dexposition-dinformations-touche-le-plugin-de-dons-give-wp\">Une faille d&rsquo;exposition d&rsquo;informations touche le plugin de dons GiveWP<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Une vuln\u00e9rabilit\u00e9 dans le plugin <a href=\"https:\/\/wordpress.org\/plugins\/give\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">GiveWP<\/a> expose les noms et emails de donateurs sur des milliers de sites WordPress. Aucun login requis. D\u00e9couvre ce qu\u2019il s\u2019est pass\u00e9, pourquoi \u00e7a fait pol\u00e9mique&#8230; et surtout, comment te prot\u00e9ger.<\/p>\n\n\n\n<div class=\"wp-block-columns is-layout-flex wp-container-core-columns-is-layout-794e3cfa wp-block-columns-is-layout-flex\">\n<div class=\"wp-block-column is-layout-flow wp-block-column-is-layout-flow\" style=\"flex-basis:66.66%\">\n<h2 class=\"wp-block-heading\" id=\"le-contexte-une-faille-serieuse-dans-un-plugin-tres-utilise\">Le contexte : une faille s\u00e9rieuse dans un plugin tr\u00e8s utilis\u00e9<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Le plugin <strong>GiveWP \u2013 Donation Plugin and Fundraising Platform<\/strong>, utilis\u00e9 par au moins 100.000 sites WordPress pour g\u00e9rer les dons, a r\u00e9cemment \u00e9t\u00e9 touch\u00e9 par une <strong>faille d\u2019exposition d\u2019informations (CWE-200)<\/strong>.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Cette vuln\u00e9rabilit\u00e9 permet \u00e0 <strong>n\u2019importe qui de r\u00e9cup\u00e9rer la liste des donateurs<\/strong> \u2013 noms, adresses emails, identifiants \u2013 sans avoir besoin d\u2019\u00eatre connect\u00e9 ou d\u2019avoir des privil\u00e8ges particuliers.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Et tout \u00e7a, simplement\u2026 en visitant un site.<\/p>\n<\/div>\n\n\n\n<div class=\"wp-block-column is-layout-flow wp-block-column-is-layout-flow\" style=\"flex-basis:33.33%\">\n<h2 class=\"wp-block-heading\">D\u00e9tails techniques<\/h2>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>CVE :<\/strong> CVE-2025-8620<\/li>\n\n\n\n<li><strong>Score CVSS :<\/strong> 5.3<\/li>\n\n\n\n<li><strong>Niveau de s\u00e9v\u00e9rit\u00e9 :<\/strong> Moyenne<\/li>\n\n\n\n<li><strong>Versions concern\u00e9es :<\/strong> Toutes jusqu\u2019\u00e0 la <strong>4.6.0 incluse<\/strong><\/li>\n\n\n\n<li><strong>Date de publication :<\/strong> 6 ao\u00fbt 2025<\/li>\n\n\n\n<li><strong>Correction apport\u00e9e dans la version :<\/strong> 4.6.1<\/li>\n<\/ul>\n<\/div>\n<\/div>\n\n\n\n<h2 class=\"wp-block-heading\">Quelles sont les cons\u00e9quences concr\u00e8tes ?<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Si tu utilises GiveWP, tu dois savoir que cette faille permet \u00e0 <strong>un visiteur lambda de collecter les informations de tes donateurs<\/strong>. Et on parle bien l\u00e0 de donn\u00e9es personnelles sensibles : pr\u00e9nom, nom, email, identifiant de donateur&#8230;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u27a1\ufe0f <strong>Risques directs :<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Violation du <strong>RGPD<\/strong><\/li>\n\n\n\n<li><strong>Fraudes<\/strong> cibl\u00e9es (phishing, usurpation d\u2019identit\u00e9)<\/li>\n\n\n\n<li><strong>Perte de confiance<\/strong> de tes donateurs<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\">R\u00e9actions (tr\u00e8s) vives sur Github<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">La communaut\u00e9 n\u2019a pas tard\u00e9 \u00e0 r\u00e9agir, et pas dans la douceur.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">La <strong><a href=\"https:\/\/github.com\/impress-org\/givewp\/issues\/8042\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">page Github de ce probl\u00e8me<\/a><\/strong> a \u00e9t\u00e9 envahie de messages de m\u00e9contentement, parfois furieux. Le support aurait d&rsquo;abord ignor\u00e9 le probl\u00e8me. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Chaque intervention du Community Manager se solde alors une pluie de <strong>downvotes \ud83d\udc4e<\/strong>.<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"869\" height=\"121\" src=\"https:\/\/portail.lrob.fr\/wp-content\/uploads\/2025\/08\/Un-dev-se-prend-une-shitstorm-givewp.jpg\" alt=\"Exemple de commentaire downvot\u00e9\" class=\"wp-image-7837\" srcset=\"https:\/\/portail.lrob.fr\/wp-content\/uploads\/2025\/08\/Un-dev-se-prend-une-shitstorm-givewp.jpg 869w, https:\/\/portail.lrob.fr\/wp-content\/uploads\/2025\/08\/Un-dev-se-prend-une-shitstorm-givewp-300x42.jpg 300w, https:\/\/portail.lrob.fr\/wp-content\/uploads\/2025\/08\/Un-dev-se-prend-une-shitstorm-givewp-768x107.jpg 768w, https:\/\/portail.lrob.fr\/wp-content\/uploads\/2025\/08\/Un-dev-se-prend-une-shitstorm-givewp-600x84.jpg 600w\" sizes=\"auto, (max-width: 869px) 100vw, 869px\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">Un utilisateur r\u00e9sume bien la situation : <em>\u00ab\u00a0This was not a minor issue. This was a massive security and privacy issue ?<\/em>\u00ab\u00a0<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">La difficult\u00e9 \u00e9tant ensuite bien-s\u00fbr pour chacun de g\u00e9rer le leak de donn\u00e9es aupr\u00e8s de ses clients m\u00e9contents&#8230;<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p class=\"wp-block-paragraph\">\u00ab\u00a0We, as the responsible party, self-reported to Troy Hunt and HIBP so they could notify the donor affected. I am receiving emails from rightfully upset donors that do not care that GiveWP was the cause of the leak, they care the Pi-hole had their data, Pi-hole caused their data to be released and thus Pi-hole will be responsible for their damages. We are getting threats of action against us under GDPR.\u00a0\u00bb<\/p>\n<cite><a href=\"https:\/\/github.com\/dschaper\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">dschaper<\/a> &#8211; From <a href=\"https:\/\/github.com\/impress-org\/givewp\/issues\/8042#issuecomment-3145429867\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">GitHub Comment<\/a><\/cite><\/blockquote>\n\n\n\n<h2 class=\"wp-block-heading\">Que faire si tu utilises GiveWP ?<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Voici <strong>les actions \u00e0 prendre imm\u00e9diatement<\/strong> :<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">\ud83d\udd04 1. Mets \u00e0 jour GiveWP vers la version 4.6.1<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">C\u2019est <strong>la seule version qui corrige<\/strong> cette vuln\u00e9rabilit\u00e9.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">\ud83d\udd0d 2. V\u00e9rifie si des donn\u00e9es ont pu \u00eatre expos\u00e9es<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Concr\u00e8tement&#8230; Si tu avais le plugin, alors le risque est pr\u00e9sent d\u00e8s qu&rsquo;un seul visiteur a pu visiter ton site. Plus le site est populaire, plus le risque est grand.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">\ud83d\udce2 3. Informe tes utilisateurs en cas de fuite<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Transparence = confiance.<\/strong> Si tu as le moindre doute sur une fuite effective, prends les devants :<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Pr\u00e9viens les donateurs concern\u00e9s (email, notification, message sur ton site\u2026)<\/li>\n\n\n\n<li>Donne-leur des conseils simples : changer leur mot de passe s\u2019ils en ont un, rester vigilants aux tentatives de phishing, etc.<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">\ud83c\udfdb\ufe0f 4. En France : Notifie la CNIL si n\u00e9cessaire<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Si la fuite repr\u00e9sente un <strong>risque pour les droits et libert\u00e9s<\/strong> des personnes concern\u00e9es (ce qui est souvent le cas avec noms + emails), <strong>tu as 72h pour la d\u00e9clarer \u00e0 la CNIL<\/strong> apr\u00e8s en avoir eu connaissance.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u26a0\ufe0f C\u2019est une obligation pr\u00e9vue par le RGPD (article 33).<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u2795 Si le risque est \u00e9lev\u00e9, tu dois \u00e9galement <strong>informer directement les personnes concern\u00e9es<\/strong>.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Plus d\u2019infos sur : <a href=\"https:\/\/www.cnil.fr\/fr\/notifier-une-violation-de-donnees-personnelles\" target=\"_blank\" rel=\"noreferrer noopener\">https:\/\/www.cnil.fr\/fr\/notifier-une-violation-de-donnees-personnelles<\/a><\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Impact chez LRob<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Chez LRob, seul un site comporte ce plugin, et le plugin y est d\u00e9sactiv\u00e9.<br>Il faut croire que nous n&rsquo;h\u00e9bergeons pas encore suffisamment d&rsquo;associations.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Aucun impact \u00e0 relever, donc.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Ressources utiles pour creuser le sujet<\/h2>\n\n\n\n<ul class=\"wp-block-list\">\n<li>\ud83d\udd17 <a href=\"https:\/\/github.com\/impress-org\/givewp\/releases\/tag\/4.6.1\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Changelog GiveWP \u2013 version 4.6.1<\/a><\/li>\n\n\n\n<li>\ud83d\udd17 <a href=\"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/give\/givewp-donation-plugin-and-fundraising-platform-460-unauthenticated-donor-data-exposure\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">D\u00e9tails sur la faille par WordFence<\/a><\/li>\n\n\n\n<li>\ud83d\udd17 <a href=\"https:\/\/github.com\/impress-org\/givewp\/issues\/8042\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Issue GitHub de la pol\u00e9mique<\/a><\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\">En conclusion : reste vigilant<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Une faille comme celle-ci nous rappelle que m\u00eame les plugins les plus populaires peuvent comporter des risques.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\ud83d\udee1\ufe0f <strong>Prot\u00e8ge tes donateurs. Renforce ta s\u00e9curit\u00e9. Reste \u00e0 jour.<\/strong><\/p>\n\n\n\n<h2 class=\"wp-block-heading\">\ud83d\udca1 Besoin d&rsquo;un coup de main c\u00f4t\u00e9 s\u00e9curit\u00e9 ?<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Marre de devoir surveiller chaque faille, chaque plugin, chaque CVE ?<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Avec les <a href=\"https:\/\/portail.lrob.fr\/en\/hebergement-web\/\">h\u00e9bergements web <strong>LRob<\/strong><\/a>, tu b\u00e9n\u00e9ficies d\u2019une <strong>surveillance automatis\u00e9e<\/strong>, d\u2019un <strong>blocage en temps r\u00e9el<\/strong> et de <strong>notifications claires<\/strong> quand un souci est d\u00e9tect\u00e9. Si besoin on s&rsquo;occupe de tout pour toi gr\u00e2ce aux <a href=\"https:\/\/portail.lrob.fr\/en\/services\/webmastering-wordpress\/\">offres webmastering<\/a>.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\ud83d\udc49 Tous nos services sur <a class=\"\" href=\"https:\/\/portail.lrob.fr\/en\/\">portail.lrob.fr\/<\/a> \ud83d\ude80\ud83d\udd12<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>","protected":false},"excerpt":{"rendered":"<p>Une vuln\u00e9rabilit\u00e9 dans le plugin GiveWP expose les noms et emails de donateurs sur des milliers de sites WordPress. Aucun login requis. D\u00e9couvre ce qu\u2019il s\u2019est pass\u00e9, pourquoi \u00e7a fait pol\u00e9mique\u2026 et surtout, comment te prot\u00e9ger.<\/p>","protected":false},"author":1,"featured_media":7841,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[45],"tags":[],"class_list":["post-7835","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-securite"],"_links":{"self":[{"href":"https:\/\/portail.lrob.fr\/en\/wp-json\/wp\/v2\/posts\/7835","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/portail.lrob.fr\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/portail.lrob.fr\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/portail.lrob.fr\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/portail.lrob.fr\/en\/wp-json\/wp\/v2\/comments?post=7835"}],"version-history":[{"count":0,"href":"https:\/\/portail.lrob.fr\/en\/wp-json\/wp\/v2\/posts\/7835\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/portail.lrob.fr\/en\/wp-json\/wp\/v2\/media\/7841"}],"wp:attachment":[{"href":"https:\/\/portail.lrob.fr\/en\/wp-json\/wp\/v2\/media?parent=7835"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/portail.lrob.fr\/en\/wp-json\/wp\/v2\/categories?post=7835"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/portail.lrob.fr\/en\/wp-json\/wp\/v2\/tags?post=7835"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}