Plugin Vulnerability Hub
Plugin 69 known issues Latest disclosed Jan 08, 2026

GiveWP – Donation Plugin and Fundraising Platform Vulnerabilities

Review known vulnerability records for the WordPress plugin GiveWP – Donation Plugin and Fundraising Platform (`give`), including severity, CVE references, affected versions, and patch status.

Known Records
69
High or Critical
14
Linked CVEs
62
Last Updated
Jan 13, 2026
Coverage Snapshot

What this page helps you verify fast

This hub clusters every indexed record for GiveWP – Donation Plugin and Fundraising Platform so operators can quickly confirm whether a disclosed issue maps to the installed slug and version range.

Patch Visibility
69 records include a published patch path.
Severity Mix
8 critical and 6 high severity findings.
Reference Workflow
Jump from the hub into the full report when you need remediation notes, CVSS vector details, or source references.
Known Vulnerabilities

Reports for GiveWP – Donation Plugin and Fundraising Platform

Sorted by latest disclosure date so newly published issues surface first.

Plugin Medium Patched: Yes CVE-2025-66533
GiveWP <= 4.13.1 - Unauthenticated Arbitrary Shortcode Execution

The The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 4.13.1. This is due to the software allowing users to execute an action that does not properly validate a value befo...

Published
Jan 08, 2026
Patched Release
4.13.2
Affected Versions
Versions up to 4.13.1
Next Step
Update to 4.13.2 or newer if supported.
Plugin Medium Patched: Yes CVE-2025-67467
GiveWP <= 4.13.1 - Cross-Site Request Forgery

The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.13.1. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated atta...

Published
Dec 23, 2025
Patched Release
4.13.2
Affected Versions
Versions up to 4.13.1
Next Step
Update to 4.13.2 or newer if supported.
Plugin High Patched: Yes CVE-2025-13206
GiveWP - Donation Plugin and Fundraising Platform <= 4.13.0 - Unauthenticated Stored Cross-Site Scripting via 'name'

The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘name’ parameter in all versions up to, and including, 4.13.0 due to insufficient input sanitization and output escaping. This makes it possible for una...

Published
Nov 18, 2025
Patched Release
4.13.1
Affected Versions
Versions up to 4.13.0
Next Step
Update to 4.13.1 or newer if supported.
Plugin Medium Patched: Yes CVE-2025-11227
GiveWP – Donation Plugin and Fundraising Platform <= 4.10.0 - Missing Authorization to Unauthenticated Forms and Campaigns Disclosure

The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 4.10.0 via the 'registerGetForm', 'registerGetForms', 'registerGetCampaign' and 'registerGetCampaigns' functions due to a missing...

Published
Oct 03, 2025
Patched Release
4.10.1
Affected Versions
Versions up to 4.10.0
Next Step
Update to 4.10.1 or newer if supported.
Plugin Medium Patched: Yes CVE-2025-11228
GiveWP – Donation Plugin and Fundraising Platform <= 4.10.0 - Missing Authorization to Unauthenticated Forms-Campaign Association

The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `registerAssociateFormsWithCampaign` function in all versions up to, and including, 4.10.0. This makes it possibl...

Published
Oct 03, 2025
Patched Release
4.10.1
Affected Versions
Versions up to 4.10.0
Next Step
Update to 4.10.1 or newer if supported.
Plugin Medium Patched: Yes CVE-2025-7221
GiveWP – Donation Plugin and Fundraising Platform <= 4.5.0 - Missing Authorization to Donation Update

The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the give_update_payment_status() function in all versions up to, and including, 4.5.0. This makes it possible for aut...

Published
Aug 20, 2025
Patched Release
4.6.1
Affected Versions
Versions up to 4.5.0
Next Step
Update to 4.6.1 or newer if supported.
Plugin Medium Patched: Yes CVE-2025-8620
GiveWP – Donation Plugin and Fundraising Platform <= 4.6.0 - Unauthenticated Donor Data Exposure

The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 4.6.0. This makes it possible for unauthenticated attackers to extract donor names, emails, and donor id. CVE-2025-47444 is a dup...

Published
Aug 05, 2025
Patched Release
4.6.1
Affected Versions
Versions up to 4.6.0
Next Step
Update to 4.6.1 or newer if supported.
Plugin Medium Patched: Yes CVE-2025-7205
GiveWP – Donation Plugin and Fundraising Platform <= 4.5.0 - Authenticated (GiveWP worker+) Stored Cross-Site Scripting

The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the donor notes parameter in all versions up to, and including, 4.5.0 due to insufficient input sanitization and output escaping. This makes it possible for...

Published
Jul 30, 2025
Patched Release
4.6.0
Affected Versions
Versions up to 4.5.0
Next Step
Update to 4.6.0 or newer if supported.
Plugin Medium Patched: Yes CVE-2025-4571
GiveWP – Donation Plugin and Fundraising Platform <= 4.3.0 - Missing Authorization To Authenticated (Contributor+) Campaign Data View And Modification

The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to unauthorized view and modification of data due to an insufficient capability check on the permissionsCheck functions in all versions up to, and including, 4.3.0. This makes it possible for...

Published
Jun 18, 2025
Patched Release
4.3.1
Affected Versions
Versions up to 4.3.0
Next Step
Update to 4.3.1 or newer if supported.
Plugin Medium Patched: Yes CVE-2025-2331
GiveWP – Donation Plugin and Fundraising Platform <= 3.22.1 - Authenticated (Subscriber+) Sensitive Information Exposure

The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.22.1 via a misconfigured capability check in the 'permissionsCheck' function. This makes it possible for authenticate...

Published
Mar 21, 2025
Patched Release
3.22.2
Affected Versions
Versions up to 3.22.1
Next Step
Update to 3.22.2 or newer if supported.
Plugin Medium Patched: Yes CVE-2025-2025
Give <= 3.22.0 - Missing Authorization to Unauthenticated Arbitrary Earning Reports Disclosure via give_reports_earnings Function

The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the give_reports_earnings() function in all versions up to, and including, 3.22.0. This makes it possible for unauthenticat...

Published
Mar 14, 2025
Patched Release
3.22.1
Affected Versions
Versions up to 3.22.0
Next Step
Update to 3.22.1 or newer if supported.
Plugin Critical Patched: Yes CVE-2025-0912
GiveWP – Donation Plugin and Fundraising Platform <= 3.19.4 - Unauthenticated PHP Object Injection

The Donations Widget plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.19.4 via deserialization of untrusted input from the Donation Form through the 'card_address' parameter. This makes it possible for unauthenticated attackers to...

Published
Mar 03, 2025
Patched Release
3.20.0
Affected Versions
Versions up to 3.19.4
Next Step
Update to 3.20.0 or newer if supported.