plugin

Give Vulnerabilities

239 known security issues reported for the Give WordPress plugin. Most recent disclosed Aug 28, 2026.

20 critical 10 high 112 medium

Running Give on your site? Check whether your installed version is affected.

Scan your site free

GiveWP – Donation Plugin and Fundraising Platform <= 4.16.7.1 - Unauthenticated PHP Object Injection to Remote Code Execution

critical

The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 4.16.7.1 via unsafe handling of serialized donor account data during the legacy donation process. An attacker without a pre-existing account can use GiveWP's registratio...

CVSS:
9.8
Affected:
up to 4.16.7.1
Fixed in:
4.16.7.2
Disclosed:
Aug 28, 2026

CVE-2026-82222 on NVD →

GiveWP <= 4.14.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes

medium

The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'give_form' shortcode in all versions up to, and including, 4.14.4. This is due to insufficient input sanitization and output escaping on the continue_button_title and display_style shortcode...

CVSS:
6.4
Affected:
up to 4.14.4
Fixed in:
4.14.5
Disclosed:
Aug 27, 2026

CVE-2026-5510 on NVD →

GiveWP – Donation Plugin and Fundraising Platform < 4.16.6 - Missing Authorization

medium

The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to 4.16.6. This makes it possible for unauthenticated attackers to perform an unauthorized action.

CVSS:
5.3
Affected:
up to 4.16.6
Fixed in:
4.16.6
Disclosed:
Aug 14, 2026

CVE-2026-73348 on NVD →

GiveWP – Donation Plugin and Fundraising Platform <= 4.16.5.1 - Missing Authorization

medium

The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 4.16.5.1. This makes it possible for unauthenticated attackers to perform an unauthorized action.

CVSS:
5.3
Affected:
up to 4.16.5.1
Fixed in:
4.16.6
Disclosed:
Aug 14, 2026

CVE-2026-73352 on NVD →

GiveWP – Donation Plugin and Fundraising Platform < 4.16.6 - Authenticated (Donor+) Stored Cross-Site Scripting

medium

The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to 4.16.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with donor-level access and above, to inject arbitrary web scri...

CVSS:
6.4
Affected:
up to 4.16.6
Fixed in:
4.16.6
Disclosed:
Aug 12, 2026

CVE-2026-73357 on NVD →

GiveWP – Donation Plugin and Fundraising Platform < 4.16.6 - Missing Authorization

medium

The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to 4.16.6. This makes it possible for unauthenticated attackers to perform an unauthorized action.

CVSS:
5.3
Affected:
up to 4.16.6
Fixed in:
4.16.6
Disclosed:
Aug 12, 2026

CVE-2026-73349 on NVD →

GiveWP – Donation Plugin and Fundraising Platform < 4.16.3 - Unauthenticated Payment Bypass

medium

The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Payment Bypass in all versions up to 4.16.3 (exclusive). This makes it possible for unauthenticated attackers to bypass payments.

CVSS:
5.3
Affected:
up to 4.16.3
Fixed in:
4.16.3
Disclosed:
Aug 4, 2026

CVE-2026-14317 on NVD →

GiveWP – Donation Plugin and Fundraising Platform <= 4.16.5 - Unauthenticated Stored Cross-Site Scripting

high

The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.16.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that...

CVSS:
7.2
Affected:
up to 4.16.5
Fixed in:
4.16.5.1
Disclosed:
Jul 31, 2026

CVE-2026-66690 on NVD →

GiveWP – Donation Plugin and Fundraising Platform < 4.16.3 - Authenticated (Custom role+) Stored Cross-Site Scripting

medium

The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to 4.16.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with custom role-level access and above, to inject arbitrary we...

CVSS:
6.4
Affected:
up to 4.16.3
Fixed in:
4.16.3
Disclosed:
Jul 30, 2026

CVE-2026-14318 on NVD →

GiveWP <= 4.16.3 - Unauthenticated Stored Cross-Site Scripting

high

The GiveWP plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.16.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an in...

CVSS:
7.2
Affected:
up to 4.16.3
Fixed in:
4.16.4
Disclosed:
Jul 27, 2026

CVE-2026-65441 on NVD →

GiveWP – Donation Plugin and Fundraising Platform <= 4.16.3 - Cross-Site Request Forgery

medium

The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.16.3. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to perform an unauthorized action via...

CVSS:
4.3
Affected:
up to 4.16.3
Fixed in:
4.16.4
Disclosed:
Jul 22, 2026

CVE-2026-65464 on NVD →

GiveWP <= 4.16.3 - Authenticated (Give Worker+) Stored Cross-Site Scripting via 'twitter_message' Sequoia Template Setting

medium

The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'twitter_message' Sequoia Template Setting in all versions up to, and including, 4.16.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attacke...

CVSS:
6.4
Affected:
up to 4.16.3
Fixed in:
4.16.4
Disclosed:
Jul 15, 2026

CVE-2026-14987 on NVD →

GiveWP <= 4.16.2 - Unauthenticated Recurring Donor Information Disclosure

medium

The GiveWP plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 4.16.2. This is due to missing anonymity check in the subscription REST API endpoint allowing retrieval of anonymous donor subscription data without authentication. This makes it possible for unauthenticate...

CVSS:
5.3
Affected:
up to 4.16.2
Fixed in:
4.16.3
Disclosed:
Jul 13, 2026

CVE-2026-14319 on NVD →

GiveWP <= 4.16.1 - Authenticated (Give Worker+) Stored Cross-Site Scripting via Sequioa Form

medium

The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'sequoia[introduction][image]' parameter in all versions up to, and including, 4.16.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attac...

CVSS:
6.4
Affected:
up to 4.16.1
Fixed in:
4.16.2
Disclosed:
Jul 1, 2026

CVE-2026-13704 on NVD →

GiveWP <= 4.15.3 - Cross-Site Request Forgery

medium

The GiveWP plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.15.3 This is due to missing nonce validation on the give_set_notification_status_handler() function. This makes it possible for unauthenticated attackers to disable donation email notifications via a forged r...

CVSS:
4.3
Affected:
up to 4.15.3
Fixed in:
4.15.4
Disclosed:
Jun 30, 2026

CVE-2026-11981 on NVD →

GiveWP <= 4.16.0 - Authenticated (Author+) Stored Cross-Site Scripting via 'block_id' Shortcode Attribute

medium

The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'block_id' (and other) shortcode attributes of the 'givewp_campaign_comments' shortcode in versions up to, and including, 4.16.0. This is due to insufficient input sanitization and output esca...

CVSS:
6.4
Affected:
up to 4.16.0
Fixed in:
4.16.1
Disclosed:
Jun 30, 2026

CVE-2026-13246 on NVD →

GiveWP – Donation Plugin and Fundraising Platform <= 4.14.5 - Unauthenticated Stored Cross-Site Scripting

high

The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.14.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that...

CVSS:
7.2
Affected:
up to 4.14.5
Fixed in:
4.14.6
Disclosed:
May 16, 2026

CVE-2026-42678 on NVD →

GiveWP – Donation Plugin and Fundraising Platform <= 4.14.2 - Reflected Cross-Site Scripting

medium

The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 4.14.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages th...

CVSS:
6.1
Affected:
up to 4.14.2
Fixed in:
4.14.3
Disclosed:
Apr 21, 2026

CVE-2026-34900 on NVD →

GiveWP <= 4.14.5 - Missing Authorization

medium

The GiveWP plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 4.14.5. This makes it possible for unauthenticated attackers to perform an unauthorized action.

CVSS:
5.3
Affected:
up to 4.14.5
Fixed in:
4.14.6
Disclosed:
Mar 2, 2026

CVE-2026-42642 on NVD →

GiveWP <= 4.13.1 - Unauthenticated Arbitrary Shortcode Execution

medium

The The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 4.13.1. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it p...

CVSS:
6.5
Affected:
up to 4.13.1
Fixed in:
4.13.2
Disclosed:
Jan 8, 2026

CVE-2025-66533 on NVD →

GiveWP < 4.13.2 - Unauthenticated Arbitrary Shortcode Execution

unknown
Affected:
up to 4.13.2
Fixed in:
4.13.2
Disclosed:
Jan 8, 2026

CVE-2025-66533 on NVD →

GiveWP <= 4.13.1 - Cross-Site Request Forgery

medium

The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.13.1. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to perform an unauthorized action...

CVSS:
4.3
Affected:
up to 4.13.1
Fixed in:
4.13.2
Disclosed:
Dec 23, 2025

CVE-2025-67467 on NVD →

GiveWP < 4.13.2 - Cross-Site Request Forgery

medium
Affected:
up to 4.13.2
Fixed in:
4.13.2
Disclosed:
Dec 23, 2025

CVE-2025-67467 on NVD →

GiveWP &#8211; Donation Plugin and Fundraising Platform [give] <= 4.13.1 (unfixed)

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in StellarWP GiveWP give allows Cross Site Request Forgery.This issue affects GiveWP: from n/a through <= 4.13.1.

Affected:
up to 4.13.1
Fix:
No patched version reported
Disclosed:
Dec 9, 2025

CVE-2025-67467 on NVD →

GiveWP &#8211; Donation Plugin and Fundraising Platform [give] <= 4.13.1 (unfixed)

unknown

[en] Improper Control of Generation of Code ('Code Injection') vulnerability in StellarWP GiveWP give allows Code Injection.This issue affects GiveWP: from n/a through <= 4.13.1.

Affected:
up to 4.13.1
Fix:
No patched version reported
Disclosed:
Dec 9, 2025

CVE-2025-66533 on NVD →

GiveWP &#8211; Donation Plugin and Fundraising Platform [give] < 4.13.1

unknown

[en] The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘name’ parameter in all versions up to, and including, 4.13.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject ar...

Affected:
up to 4.13.1
Fixed in:
4.13.1
Disclosed:
Nov 19, 2025

CVE-2025-13206 on NVD →

GiveWP - Donation Plugin and Fundraising Platform <= 4.13.0 - Unauthenticated Stored Cross-Site Scripting via 'name'

high

The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘name’ parameter in all versions up to, and including, 4.13.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitra...

CVSS:
7.2
Affected:
up to 4.13.0
Fixed in:
4.13.1
Disclosed:
Nov 18, 2025

CVE-2025-13206 on NVD →

GiveWP < 4.13.1 - Unauthenticated Stored XSS via 'name'

medium
Affected:
up to 4.13.1
Fixed in:
4.13.1
Disclosed:
Nov 18, 2025

CVE-2025-13206 on NVD →

GiveWP &#8211; Donation Plugin and Fundraising Platform [give] < 4.10.1

unknown

[en] The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 4.10.0 via the 'registerGetForm', 'registerGetForms', 'registerGetCampaign' and 'registerGetCampaigns' functions due to a missing capability check. This makes it po...

Affected:
up to 4.10.1
Fixed in:
4.10.1
Disclosed:
Oct 4, 2025

CVE-2025-11227 on NVD →

GiveWP &#8211; Donation Plugin and Fundraising Platform [give] < 4.10.1

unknown

[en] The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `registerAssociateFormsWithCampaign` function in all versions up to, and including, 4.10.0. This makes it possible for unauthenticated attackers to...

Affected:
up to 4.10.1
Fixed in:
4.10.1
Disclosed:
Oct 4, 2025

CVE-2025-11228 on NVD →

GiveWP – Donation Plugin and Fundraising Platform <= 4.10.0 - Missing Authorization to Unauthenticated Forms and Campaigns Disclosure

medium

The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 4.10.0 via the 'registerGetForm', 'registerGetForms', 'registerGetCampaign' and 'registerGetCampaigns' functions due to a missing capability check. This makes it possibl...

CVSS:
6.5
Affected:
up to 4.10.0
Fixed in:
4.10.1
Disclosed:
Oct 3, 2025

CVE-2025-11227 on NVD →

GiveWP – Donation Plugin and Fundraising Platform <= 4.10.0 - Missing Authorization to Unauthenticated Forms-Campaign Association

medium

The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `registerAssociateFormsWithCampaign` function in all versions up to, and including, 4.10.0. This makes it possible for unauthenticated attackers to assoc...

CVSS:
5.3
Affected:
up to 4.10.0
Fixed in:
4.10.1
Disclosed:
Oct 3, 2025

CVE-2025-11228 on NVD →

GiveWP – Donation Plugin and Fundraising Platform < 4.10.1 - Missing Authorization to Unauthenticated Forms-Campaign Association

medium
Affected:
up to 4.10.1
Fixed in:
4.10.1
Disclosed:
Oct 3, 2025

CVE-2025-11228 on NVD →

GiveWP < 4.10.1 - Unauthenticated Forms and Campaigns Disclosure

unknown
Affected:
up to 4.10.1
Fixed in:
4.10.1
Disclosed:
Oct 3, 2025

CVE-2025-11227 on NVD →

GiveWP – Donation Plugin and Fundraising Platform <= 4.5.0 - Missing Authorization to Donation Update

medium

The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the give_update_payment_status() function in all versions up to, and including, 4.5.0. This makes it possible for authenticated attackers, with GiveWP Worker...

CVSS:
4.3
Affected:
up to 4.5.0
Fixed in:
4.6.1
Disclosed:
Aug 20, 2025

CVE-2025-7221 on NVD →

GiveWP < 4.6.1 - Missing Authorization to Donation Update

medium
Affected:
up to 4.6.1
Fixed in:
4.6.1
Disclosed:
Aug 20, 2025

CVE-2025-7221 on NVD →

GiveWP &#8211; Donation Plugin and Fundraising Platform [give] < 4.6.1

unknown

[en] Insertion of Sensitive Information Into Sent Data vulnerability in Liquid Web GiveWP allows Retrieve Embedded Sensitive Data.This issue affects GiveWP: from n/a before 4.6.1.

Affected:
up to 4.6.1
Fixed in:
4.6.1
Disclosed:
Aug 12, 2025

CVE-2025-47444 on NVD →

GiveWP – Donation Plugin and Fundraising Platform <= 4.6.0 - Unauthenticated Donor Data Exposure

medium

The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 4.6.0. This makes it possible for unauthenticated attackers to extract donor names, emails, and donor id. CVE-2025-47444 is a duplicate of this issue. CVE-2025-47444 is...

CVSS:
5.3
Affected:
up to 4.6.0
Fixed in:
4.6.1
Disclosed:
Aug 5, 2025

CVE-2025-8620 on NVD →

GiveWP – Donation Plugin and Fundraising Platform < 4.6.1 - Unauthenticated Donor Data Exposure

unknown
Affected:
up to 4.6.1
Fixed in:
4.6.1
Disclosed:
Aug 5, 2025

CVE-2025-8620 on NVD →

GiveWP – Donation Plugin and Fundraising Platform <= 4.5.0 - Authenticated (GiveWP worker+) Stored Cross-Site Scripting

medium

The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the donor notes parameter in all versions up to, and including, 4.5.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with GiveWP wo...

CVSS:
5.4
Affected:
up to 4.5.0
Fixed in:
4.6.0
Disclosed:
Jul 30, 2025

CVE-2025-7205 on NVD →

GiveWP – Donation Plugin and Fundraising Platform < 4.6.0 - Authenticated (GiveWP worker+) Stored Cross-Site Scripting

medium
Affected:
up to 4.6.0
Fixed in:
4.6.0
Disclosed:
Jul 30, 2025

CVE-2025-7205 on NVD →

GiveWP – Donation Plugin and Fundraising Platform <= 4.3.0 - Missing Authorization To Authenticated (Contributor+) Campaign Data View And Modification

medium

The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to unauthorized view and modification of data due to an insufficient capability check on the permissionsCheck functions in all versions up to, and including, 4.3.0. This makes it possible for authenticated attackers, with Contribut...

CVSS:
5.4
Affected:
up to 4.3.0
Fixed in:
4.3.1
Disclosed:
Jun 18, 2025

CVE-2025-4571 on NVD →

GiveWP – Donation Plugin and Fundraising Platform < 4.3.1 - Missing Authorization To Authenticated (Contributor+) Campaign Data View And Modification

medium
Affected:
up to 4.3.1
Fixed in:
4.3.1
Disclosed:
Jun 18, 2025

CVE-2025-4571 on NVD →

GiveWP – Donation Plugin and Fundraising Platform <= 3.22.1 - Authenticated (Subscriber+) Sensitive Information Exposure

medium

The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.22.1 via a misconfigured capability check in the 'permissionsCheck' function. This makes it possible for authenticated attackers, with Subscriber-level acces...

CVSS:
5.3
Affected:
up to 3.22.1
Fixed in:
3.22.2
Disclosed:
Mar 21, 2025

CVE-2025-2331 on NVD →

GiveWP – Donation Plugin and Fundraising Platform < 3.22.2 - Authenticated (Subscriber+) Sensitive Information Exposure

medium
Affected:
up to 3.22.2
Fixed in:
3.22.2
Disclosed:
Mar 21, 2025

CVE-2025-2331 on NVD →

Give <= 3.22.0 - Missing Authorization to Unauthenticated Arbitrary Earning Reports Disclosure via give_reports_earnings Function

medium

The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the give_reports_earnings() function in all versions up to, and including, 3.22.0. This makes it possible for unauthenticated attackers to disclose sensitive infor...

CVSS:
6.5
Affected:
up to 3.22.0
Fixed in:
3.22.1
Disclosed:
Mar 14, 2025

CVE-2025-2025 on NVD →

Give < 3.22.1 - Missing Authorization to Unauthenticated Arbitrary Earning Reports Disclosure via give_reports_earnings Function

medium
Affected:
up to 3.22.1
Fixed in:
3.22.1
Disclosed:
Mar 14, 2025

CVE-2025-2025 on NVD →

GiveWP – Donation Plugin and Fundraising Platform <= 3.19.4 - Unauthenticated PHP Object Injection

critical

The Donations Widget plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.19.4 via deserialization of untrusted input from the Donation Form through the 'card_address' parameter. This makes it possible for unauthenticated attackers to inject a PHP Object. The additional pre...

CVSS:
9.8
Affected:
up to 3.19.4
Fixed in:
3.20.0
Disclosed:
Mar 3, 2025

CVE-2025-0912 on NVD →

GiveWP < 3.20.0 - Unauthenticated PHP Object Injection

critical
Affected:
up to 3.20.0
Fixed in:
3.20.0
Disclosed:
Mar 3, 2025

CVE-2025-0912 on NVD →

GiveWP &#8211; Donation Plugin and Fundraising Platform [give] < 3.19.4

unknown

[en] Deserialization of Untrusted Data vulnerability in GiveWP GiveWP allows Object Injection.This issue affects GiveWP: from n/a through 3.19.3.

Affected:
up to 3.19.4
Fixed in:
3.19.4
Disclosed:
Jan 13, 2025

CVE-2025-22777 on NVD →

GiveWP &#8211; Donation Plugin and Fundraising Platform [give] < 3.19.3

unknown

[en] The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.19.2 via deserialization of untrusted input from the donation form like 'firstName'. This makes it possible for unauthenticated attackers to inject a PHP Object....

Affected:
up to 3.19.3
Fixed in:
3.19.3
Disclosed:
Jan 11, 2025

CVE-2024-12877 on NVD →

GiveWP – Donation Plugin and Fundraising Platform <= 3.19.3 - Unauthenticated PHP Object Injection

critical

The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.19.3 via deserialization of untrusted input from the donation form through the 'company' parameter. This makes it possible for unauthenticated attackers to inject a PH...

CVSS:
9.8
Affected:
up to 3.19.3
Fixed in:
3.19.4
Disclosed:
Jan 10, 2025

CVE-2025-22777 on NVD →

GiveWP – Donation Plugin and Fundraising Platform <= 3.19.2 - Unauthenticated PHP Object Injection

critical

The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.19.2 via deserialization of untrusted input from the donation form like 'firstName'. This makes it possible for unauthenticated attackers to inject a PHP Object. The a...

CVSS:
9.8
Affected:
up to 3.19.2
Fixed in:
3.19.3
Disclosed:
Jan 10, 2025

CVE-2024-12877 on NVD →

GiveWP < 3.19.3 - Unauthenticated PHP Object Injection

critical
Affected:
up to 3.19.3
Fixed in:
3.19.3
Disclosed:
Jan 10, 2025

CVE-2024-12877 on NVD →

GiveWP < 3.19.4 - Unauthenticated PHP Object Injection

critical
Affected:
up to 3.19.4
Fixed in:
3.19.4
Disclosed:
Jan 10, 2025

CVE-2025-22777 on NVD →

GiveWP &#8211; Donation Plugin and Fundraising Platform [give] < 2.25.2

unknown

[en] Missing Authorization vulnerability in Liquid Web / StellarWP GiveWP.This issue affects GiveWP: from n/a through 2.25.1.

Affected:
up to 2.25.2
Fixed in:
2.25.2
Disclosed:
Jan 2, 2025

CVE-2023-23672 on NVD →

GiveWP &#8211; Donation Plugin and Fundraising Platform [give] < 2.33.2

unknown

[en] Missing Authorization vulnerability in GiveWP GiveWP allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects GiveWP: from n/a through 2.33.1.

Affected:
up to 2.33.2
Fixed in:
2.33.2
Disclosed:
Jan 2, 2025

CVE-2023-47183 on NVD →

GiveWP &#8211; Donation Plugin and Fundraising Platform [give] < 3.19.0

unknown

[en] The GiveWP WordPress plugin before 3.19.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

Affected:
up to 3.19.0
Fixed in:
3.19.0
Disclosed:
Dec 27, 2024

CVE-2024-11921 on NVD →

GiveWP – Donation Plugin and Fundraising Platform <= 3.18.0 - Reflected Cross-Site Scripting

medium

The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'give-run-migration' parameter in all versions up to, and including, 3.18.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers...

CVSS:
6.1
Affected:
up to 3.18.0
Fixed in:
3.19.0
Disclosed:
Dec 6, 2024

CVE-2024-11921 on NVD →

Give < 3.19.0 - Reflected XSS

medium
Affected:
up to 3.19.0
Fixed in:
3.19.0
Disclosed:
Dec 6, 2024

CVE-2024-11921 on NVD →

GiveWP &#8211; Donation Plugin and Fundraising Platform [give] < 3.16.4

unknown

[en] The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.16.3 via deserialization of untrusted input from the give_company_name parameter. This makes it possible for unauthenticated attackers to inject a PHP Object. The...

Affected:
up to 3.16.4
Fixed in:
3.16.4
Disclosed:
Oct 16, 2024

CVE-2024-9634 on NVD →

GiveWP – Donation Plugin and Fundraising Platform <= 3.16.3 - Unauthenticated PHP Object Injection to Remote Code Execution

critical

The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.16.3 via deserialization of untrusted input from the give_company_name parameter. This makes it possible for unauthenticated attackers to inject a PHP Object. The addi...

CVSS:
9.8
Affected:
up to 3.16.3
Fixed in:
3.16.4
Disclosed:
Oct 15, 2024

CVE-2024-9634 on NVD →

GiveWP < 3.16.4 - Unauthenticated PHP Object Injection to Remote Code Execution

critical
Affected:
up to 3.16.4
Fixed in:
3.16.4
Disclosed:
Oct 15, 2024

CVE-2024-9634 on NVD →

GiveWP &#8211; Donation Plugin and Fundraising Platform [give] < 3.16.2

unknown

[en] The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.16.1 via deserialization of untrusted input via several parameters like 'give_title' and 'card_address'. This makes it possible for unauthenticated attackers to i...

Affected:
up to 3.16.2
Fixed in:
3.16.2
Disclosed:
Sep 28, 2024

CVE-2024-8353 on NVD →

GiveWP – Donation Plugin and Fundraising Platform <= 3.16.1 - Unauthenticated PHP Object Injection

critical

The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.16.1 via deserialization of untrusted input via several parameters like 'give_title' and 'card_address'. This makes it possible for unauthenticated attackers to inject...

CVSS:
9.8
Affected:
up to 3.16.1
Fixed in:
3.16.2
Disclosed:
Sep 27, 2024

CVE-2024-8353 on NVD →

GiveWP &#8211; Donation Plugin and Fundraising Platform [give] < 3.16.2

unknown

[en] The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to time-based SQL Injection via the ‘order’ parameter in all versions up to, and including, 3.16.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This...

Affected:
up to 3.16.2
Fixed in:
3.16.2
Disclosed:
Sep 27, 2024

CVE-2024-9130 on NVD →

GiveWP – Donation Plugin and Fundraising Platform < 3.16.2 - Unauthenticated PHP Object Injection

critical
Affected:
up to 3.16.2
Fixed in:
3.16.2
Disclosed:
Sep 27, 2024

CVE-2024-8353 on NVD →

GiveWP – Donation Plugin and Fundraising Platform <= 3.16.1 - Authenticated (GiveWP Manager+) SQL Injection via order Parameter

high

The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to time-based SQL Injection via the ‘order’ parameter in all versions up to, and including, 3.16.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This make...

CVSS:
7.2
Affected:
up to 3.16.1
Fixed in:
3.16.2
Disclosed:
Sep 26, 2024

CVE-2024-9130 on NVD →

GiveWP – Donation Plugin and Fundraising Platform < 3.16.2 - Authenticated (GiveWP Manager+) SQL Injection via order Parameter

critical
Affected:
up to 3.16.2
Fixed in:
3.16.2
Disclosed:
Sep 26, 2024

CVE-2024-9130 on NVD →

GiveWP <= 3.15.1 - Cross-Site Request Forgery

medium

The GiveWP plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.15.1. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to perform an action they should not have access to via a forged request granted...

CVSS:
4.3
Affected:
up to 3.15.1
Fixed in:
3.16.0
Disclosed:
Sep 25, 2024

CVE-2024-47315 on NVD →

GiveWP &#8211; Donation Plugin and Fundraising Platform [give] < 3.16.0

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in GiveWP.This issue affects GiveWP: from n/a through 3.15.1.

Affected:
up to 3.16.0
Fixed in:
3.16.0
Disclosed:
Sep 25, 2024

CVE-2024-47315 on NVD →

GiveWP < 3.16.0 - Cross-Site Request Forgery

medium
Affected:
up to 3.16.0
Fixed in:
3.16.0
Disclosed:
Sep 25, 2024

CVE-2024-47315 on NVD →

GiveWP &#8211; Donation Plugin and Fundraising Platform [give] < 3.16.0

unknown

[en] The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 3.15.1. This is due to the plugin utilizing Symfony and leaving display_errors on within test files. This makes it possible for unauthenticated attackers to retriev...

Affected:
up to 3.16.0
Fixed in:
3.16.0
Disclosed:
Aug 29, 2024

CVE-2024-6551 on NVD →

GiveWP <= 3.15.1 - Unauthenticated Full Path Disclosure

medium

The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 3.15.1. This is due to the plugin utilizing Symfony and leaving display_errors on within test files. This makes it possible for unauthenticated attackers to retrieve the...

CVSS:
5.3
Affected:
up to 3.15.1
Fixed in:
3.16.0
Disclosed:
Aug 28, 2024

CVE-2024-6551 on NVD →

GiveWP < 3.16.0 - Unauthenticated Full Path Disclosure

unknown
Affected:
up to 3.16.0
Fixed in:
3.16.0
Disclosed:
Aug 28, 2024

CVE-2024-6551 on NVD →

GiveWP &#8211; Donation Plugin and Fundraising Platform [give] < 3.14.2

unknown

[en] The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to unauthorized access and deletion of data due to a missing capability check on the 'handle_request' function in all versions up to, and including, 3.14.1. This makes it possible for authenticated attackers, with Subscriber-l...

Affected:
up to 3.14.2
Fixed in:
3.14.2
Disclosed:
Aug 20, 2024

CVE-2024-5941 on NVD →

GiveWP &#8211; Donation Plugin and Fundraising Platform [give] < 3.14.2

unknown

[en] The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.14.1 via deserialization of untrusted input from the 'give_title' parameter. This makes it possible for unauthenticated attackers to inject a PHP Object. The addi...

Affected:
up to 3.14.2
Fixed in:
3.14.2
Disclosed:
Aug 20, 2024

CVE-2024-5932 on NVD →

GiveWP &#8211; Donation Plugin and Fundraising Platform [give] < 3.14.0

unknown

[en] The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'setup_wizard' function in all versions up to, and including, 3.13.0. This makes it possible for unauthenticated attackers to read the setup wizard admini...

Affected:
up to 3.14.0
Fixed in:
3.14.0
Disclosed:
Aug 20, 2024

CVE-2024-5939 on NVD →

GiveWP &#8211; Donation Plugin and Fundraising Platform [give] < 3.14.0

unknown

[en] The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'handle_request' function in all versions up to, and including, 3.13.0. This makes it possible for unauthenticated attackers to edit event ticket se...

Affected:
up to 3.14.0
Fixed in:
3.14.0
Disclosed:
Aug 20, 2024

CVE-2024-5940 on NVD →

GiveWP – Donation Plugin and Fundraising Platform <= 3.14.1 - Unauthenticated PHP Object Injection to Remote Code Execution

critical

The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.14.1 via deserialization of untrusted input from the 'give_title' parameter. This makes it possible for unauthenticated attackers to inject a PHP Object. The additiona...

CVSS:
10
Affected:
up to 3.14.1
Fixed in:
3.14.2
Disclosed:
Aug 19, 2024

CVE-2024-5932 on NVD →

GiveWP – Donation Plugin and Fundraising Platform <= 3.13.0 - Missing Authorization to Unauthenticated Event Settings Update

medium

The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'handle_request' function in all versions up to, and including, 3.13.0. This makes it possible for unauthenticated attackers to edit event ticket setting...

CVSS:
6.5
Affected:
up to 3.13.0
Fixed in:
3.14.0
Disclosed:
Aug 19, 2024

CVE-2024-5940 on NVD →

GiveWP – Donation Plugin and Fundraising Platform <= 3.14.1 - Missing Authorization to Authenticated (Subscriber+) Limited File Deletion

medium

The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to unauthorized access and deletion of data due to a missing capability check on the 'handle_request' function in all versions up to, and including, 3.14.1. This makes it possible for authenticated attackers, with Subscriber-level...

CVSS:
5.4
Affected:
up to 3.14.1
Fixed in:
3.14.2
Disclosed:
Aug 19, 2024

CVE-2024-5941 on NVD →

GiveWP – Donation Plugin and Fundraising Platform <= 3.13.0 - Missing Authorization to Limited Information Exposure

medium

The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'setup_wizard' function in all versions up to, and including, 3.13.0. This makes it possible for unauthenticated attackers to read the setup wizard administrat...

CVSS:
5.3
Affected:
up to 3.13.0
Fixed in:
3.14.0
Disclosed:
Aug 19, 2024

CVE-2024-5939 on NVD →

GiveWP &#8211; Donation Plugin and Fundraising Platform [give] < 3.14.2

unknown

[en] Deserialization of Untrusted Data vulnerability in Liquid Web GiveWP allows Object Injection.This issue affects GiveWP: from n/a through 3.14.1.

Affected:
up to 3.14.2
Fixed in:
3.14.2
Disclosed:
Aug 19, 2024

CVE-2024-37099 on NVD →

GiveWP – Donation Plugin and Fundraising Platform < 3.14.2 - Missing Authorization to Authenticated (Subscriber+) Limited File Deletion

medium
Affected:
up to 3.14.2
Fixed in:
3.14.2
Disclosed:
Aug 19, 2024

CVE-2024-5941 on NVD →

GiveWP – Donation Plugin and Fundraising Platform < 3.14.0 - Missing Authorization to Limited Information Exposure

medium
Affected:
up to 3.14.0
Fixed in:
3.14.0
Disclosed:
Aug 19, 2024

CVE-2024-5939 on NVD →

GiveWP – Donation Plugin and Fundraising Platform < 3.14.0 - Missing Authorization to Unauthenticated Event Settings Update

medium
Affected:
up to 3.14.0
Fixed in:
3.14.0
Disclosed:
Aug 19, 2024

CVE-2024-5940 on NVD →

GiveWP < 3.14.2 - Unauthenticated PHP Object Injection to RCE

critical
Affected:
up to 3.14.2
Fixed in:
3.14.2
Disclosed:
Aug 19, 2024

CVE-2024-5932 on NVD →

GiveWP <= 3.14.1 - Unauthenticated PHP Object Injection

high

The GiveWP plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 3.14.1 via deserialization of untrusted input. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP chain is present in the vulnerable software. If a POP chain is present via an a...

CVSS:
8.1
Affected:
up to 3.14.1
Fixed in:
3.14.2
Disclosed:
Aug 9, 2024

CVE-2024-37099 on NVD →

GiveWP &#8211; Donation Plugin and Fundraising Platform [give] < 3.14.0

unknown

[en] The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.13.0 via the 'handleRequest' function due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with Giv...

Affected:
up to 3.14.0
Fixed in:
3.14.0
Disclosed:
Jul 19, 2024

CVE-2024-5977 on NVD →

GiveWP – Donation Plugin and Fundraising Platform <= 3.13.0 - Insecure Direct Object Reference to Authenticated (GiveWP Worker+) Arbitrary Post Actions

medium

The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.13.0 via the 'handleRequest' function due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with GiveWP W...

CVSS:
5.4
Affected:
up to 3.13.0
Fixed in:
3.14.0
Disclosed:
Jul 18, 2024

CVE-2024-5977 on NVD →

GiveWP – Donation Plugin and Fundraising Platform < 3.14.0 - Insecure Direct Object Reference to Authenticated (GiveWP Worker+) Arbitrary Post Actions

unknown
Affected:
up to 3.14.0
Fixed in:
3.14.0
Disclosed:
Jul 18, 2024

CVE-2024-5977 on NVD →

GiveWP &#8211; Donation Plugin and Fundraising Platform [give] < 3.12.1

unknown

[en] Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in GiveWP allows Reflected XSS.This issue affects GiveWP: from n/a through 3.12.0.

Affected:
up to 3.12.1
Fixed in:
3.12.1
Disclosed:
Jun 8, 2024

CVE-2024-35679 on NVD →

GiveWP – Donation Plugin and Fundraising Platform <= 3.12.0 - Reflected Cross-Site Scripting

medium

The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, 3.12.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in page...

CVSS:
6.1
Affected:
up to 3.12.0
Fixed in:
3.12.1
Disclosed:
Jun 6, 2024

CVE-2024-35679 on NVD →

GiveWP – Donation Plugin and Fundraising Platform < 3.12.1 - Reflected Cross-Site Scripting

medium
Affected:
up to 3.12.1
Fixed in:
3.12.1
Disclosed:
Jun 6, 2024

CVE-2024-35679 on NVD →

GiveWP &#8211; Donation Plugin and Fundraising Platform [give] < 3.11.0

unknown

[en] The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'give_form' shortcode when used with a legacy form in all versions up to, and including, 3.10.0 due to insufficient input sanitization and output escaping on user supplied attrib...

Affected:
up to 3.11.0
Fixed in:
3.11.0
Disclosed:
May 18, 2024

CVE-2024-3714 on NVD →

GiveWP – Donation Plugin and Fundraising Platform <= 3.10.0 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'give_form' shortcode when used with a legacy form in all versions up to, and including, 3.10.0 due to insufficient input sanitization and output escaping on user supplied attributes....

CVSS:
6.4
Affected:
up to 3.10.0
Fixed in:
3.11.0
Disclosed:
May 17, 2024

CVE-2024-3714 on NVD →

GiveWP &#8211; Donation Plugin and Fundraising Platform [give] < 2.33.1

unknown

[en] Improper Privilege Management vulnerability in GiveWP allows Privilege Escalation.This issue affects GiveWP: from n/a through 2.33.0.

Affected:
up to 2.33.1
Fixed in:
2.33.1
Disclosed:
May 17, 2024

CVE-2023-41665 on NVD →

GiveWP < 3.11.0 - Contributor+ Stored XSS

medium
Affected:
up to 3.11.0
Fixed in:
3.11.0
Disclosed:
May 17, 2024

CVE-2024-3714 on NVD →

GiveWP – Donation Plugin and Fundraising Platform <= 3.4.2 - Authenticated (GiveWP Manager+) PHP Object Injection

high

The GiveWP plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.4.2 via deserialization of untrusted input. This makes it possible for authenticated attackers, with give manager-level access and above, to inject a PHP Object. No known POP chain is present in the vulnerable...

CVSS:
8.8
Affected:
up to 3.4.2
Fixed in:
3.5.0
Disclosed:
Apr 26, 2024

CVE-2024-30229 on NVD →

GiveWP – Donation Plugin and Fundraising Platform < 3.5.0 - Authenticated (GiveWP Manager+) PHP Object Injection

critical
Affected:
up to 3.5.0
Fixed in:
3.5.0
Disclosed:
Apr 26, 2024

CVE-2024-30229 on NVD →

GiveWP &#8211; Donation Plugin and Fundraising Platform [give] < 3.7.0

unknown

[en] The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'give_form' shortcode in all versions up to, and including, 3.6.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible f...

Affected:
up to 3.7.0
Fixed in:
3.7.0
Disclosed:
Apr 13, 2024

CVE-2024-1957 on NVD →

GiveWP – Donation Plugin and Fundraising Platform <= 3.6.1 -- Authenticated(Contributor+) Stored Cross-Site Scripting via Shortcode

medium

The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'give_form' shortcode in all versions up to, and including, 3.6.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for au...

CVSS:
6.4
Affected:
up to 3.6.1
Fixed in:
3.7.0
Disclosed:
Apr 12, 2024

CVE-2024-1957 on NVD →

GiveWP &#8211; Donation Plugin and Fundraising Platform [give] < 2.25.2

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in GiveWP allows Stored XSS.This issue affects GiveWP: from n/a through 2.25.1.

Affected:
up to 2.25.2
Fixed in:
2.25.2
Disclosed:
Apr 12, 2024

CVE-2022-40211 on NVD →

GiveWP – Donation Plugin and Fundraising Platform < 3.7.0 - Contributor+ Stored Cross-Site Scripting via Shortcode

medium
Affected:
up to 3.7.0
Fixed in:
3.7.0
Disclosed:
Apr 12, 2024

CVE-2024-1957 on NVD →

GiveWP &#8211; Donation Plugin and Fundraising Platform [give] < 3.6.0

unknown

[en] The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 3.5.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authen...

Affected:
up to 3.6.0
Fixed in:
3.6.0
Disclosed:
Apr 9, 2024

CVE-2024-1424 on NVD →

GiveWP &#8211; Donation Plugin and Fundraising Platform [give] < 3.5.0

unknown

[en] Deserialization of Untrusted Data vulnerability in GiveWP.This issue affects GiveWP: from n/a through 3.4.2.

Affected:
up to 3.5.0
Fixed in:
3.5.0
Disclosed:
Mar 28, 2024

CVE-2024-30229 on NVD →

GiveWP – Donation Plugin and Fundraising Platform <= 3.5.1 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 3.5.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticat...

CVSS:
6.4
Affected:
up to 3.5.1
Fixed in:
3.6.0
Disclosed:
Mar 19, 2024

CVE-2024-1424 on NVD →

GiveWP – Donation Plugin and Fundraising Platform < 3.6.0 - Contributor+ Stored XSS

medium
Affected:
up to 3.6.0
Fixed in:
3.6.0
Disclosed:
Mar 19, 2024

CVE-2024-1424 on NVD →

GiveWP <= 3.3.1 - Reflected Cross-Site Scripting

medium

The GiveWP plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 3.3.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a...

CVSS:
6.1
Affected:
up to 3.3.1
Fixed in:
3.4.0
Disclosed:
Mar 15, 2024

CVE-2024-27987 on NVD →

GiveWP &#8211; Donation Plugin and Fundraising Platform [give] < 3.4.0

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in GiveWP Give allows Reflected XSS.This issue affects Give: from n/a through 3.3.1.

Affected:
up to 3.4.0
Fixed in:
3.4.0
Disclosed:
Mar 15, 2024

CVE-2024-27987 on NVD →

GiveWP < 3.4.0 - Reflected Cross-Site Scripting

medium
Affected:
up to 3.4.0
Fixed in:
3.4.0
Disclosed:
Mar 15, 2024

CVE-2024-27987 on NVD →

GiveWP &#8211; Donation Plugin and Fundraising Platform [give] < 3.3.0

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in GiveWP GiveWP – Donation Plugin and Fundraising Platform allows Stored XSS.This issue affects GiveWP – Donation Plugin and Fundraising Platform: from n/a through 3.2.2.

Affected:
up to 3.3.0
Fixed in:
3.3.0
Disclosed:
Feb 10, 2024

CVE-2023-51415 on NVD →

GiveWP <= 3.2.2 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The GiveWP plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.2.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will...

CVSS:
6.4
Affected:
up to 3.2.2
Fixed in:
3.3.0
Disclosed:
Jan 19, 2024

CVE-2023-51415 on NVD →

GiveWP < 3.3.0 - Contributor+ Stored XSS

medium
Affected:
up to 3.3.0
Fixed in:
3.3.0
Disclosed:
Jan 19, 2024

CVE-2023-51415 on NVD →

GiveWP &#8211; Donation Plugin and Fundraising Platform [give] < 2.24.1

unknown

[en] The GiveWP WordPress plugin before 2.24.1 does not properly escape user input before it reaches SQL queries, which could let unauthenticated attackers perform SQL Injection attacks

Affected:
up to 2.24.1
Fixed in:
2.24.1
Disclosed:
Jan 16, 2024

CVE-2023-0224 on NVD →

GiveWP &#8211; Donation Plugin and Fundraising Platform [give] < 2.33.4

unknown

[en] The GiveWP plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.33.3. This is due to missing or incorrect nonce validation on the give_sendwp_remote_install_handler function. This makes it possible for unauthenticated attackers to install and activate the SendWP plug...

Affected:
up to 2.33.4
Fixed in:
2.33.4
Disclosed:
Jan 11, 2024

CVE-2023-4246 on NVD →

GiveWP &#8211; Donation Plugin and Fundraising Platform [give] < 2.33.4

unknown

[en] The GiveWP plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.33.3. This is due to missing or incorrect nonce validation on the give_sendwp_disconnect function. This makes it possible for unauthenticated attackers to deactivate the SendWP plugin via a forged reques...

Affected:
up to 2.33.4
Fixed in:
2.33.4
Disclosed:
Jan 11, 2024

CVE-2023-4247 on NVD →

GiveWP &#8211; Donation Plugin and Fundraising Platform [give] < 2.33.4

unknown

[en] The GiveWP plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.33.3. This is due to missing or incorrect nonce validation on the give_stripe_disconnect_connect_stripe_account function. This makes it possible for unauthenticated attackers to deactivate the plugin's s...

Affected:
up to 2.33.4
Fixed in:
2.33.4
Disclosed:
Jan 11, 2024

CVE-2023-4248 on NVD →

GiveWP &#8211; Donation Plugin and Fundraising Platform [give] < 2.26.0

unknown

[en] Deserialization of Untrusted Data vulnerability in GiveWP GiveWP – Donation Plugin and Fundraising Platform.This issue affects GiveWP – Donation Plugin and Fundraising Platform: from n/a through 2.25.3.

Affected:
up to 2.26.0
Fixed in:
2.26.0
Disclosed:
Dec 28, 2023

CVE-2023-32513 on NVD →

GiveWP &#8211; Donation Plugin and Fundraising Platform [give] < 2.25.2

unknown

[en] Server-Side Request Forgery (SSRF) vulnerability in GiveWP GiveWP – Donation Plugin and Fundraising Platform.This issue affects GiveWP – Donation Plugin and Fundraising Platform: from n/a through 2.25.1.

Affected:
up to 2.25.2
Fixed in:
2.25.2
Disclosed:
Dec 18, 2023

CVE-2022-40312 on NVD →

GiveWP &#8211; Donation Plugin and Fundraising Platform [give] < 2.25.2

unknown

[en] Improper Neutralization of Formula Elements in a CSV File vulnerability in GiveWP.This issue affects GiveWP: from n/a through 2.25.1.

Affected:
up to 2.25.2
Fixed in:
2.25.2
Disclosed:
Nov 7, 2023

CVE-2023-22719 on NVD →

GiveWP <= 2.33.3 - Cross-Site Request Forgery to Stripe Integration Deletion

medium

The GiveWP plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.33.3. This is due to missing or incorrect nonce validation on the give_stripe_disconnect_connect_stripe_account function. This makes it possible for unauthenticated attackers to deactivate the plugin's stripe...

CVSS:
5.4
Affected:
up to 2.33.3
Fixed in:
2.33.4
Disclosed:
Oct 31, 2023

CVE-2023-4248 on NVD →

GiveWP <= 2.33.3 - Cross-Site Request Forgery to plugin deactivation

medium

The GiveWP plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.33.3. This is due to missing or incorrect nonce validation on the give_sendwp_disconnect function. This makes it possible for unauthenticated attackers to deactivate the SendWP plugin via a forged request gra...

CVSS:
5.4
Affected:
up to 2.33.3
Fixed in:
2.33.4
Disclosed:
Oct 31, 2023

CVE-2023-4247 on NVD →

GiveWP <= 2.33.1 - Missing Authorization via handleBeforeGateway

medium

The GiveWP plugin for WordPress is vulnerable to unauthorized donation form access due to a missing check on the handleBeforeGateway function that would ensure that a donation form can be used and is not trashed in versions up to, and including, 2.33.1. There is no real security impact, but such trashed donation forms...

CVSS:
5.3
Affected:
up to 2.33.1
Fixed in:
2.33.2
Disclosed:
Oct 31, 2023

CVE-2023-47183 on NVD →

GiveWP <= 2.33.3 - Cross-Site Request Forgery to plugin installation

medium

The GiveWP plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.33.3. This is due to missing or incorrect nonce validation on the give_sendwp_remote_install_handler function. This makes it possible for unauthenticated attackers to install and activate the SendWP plugin vi...

CVSS:
4.3
Affected:
up to 2.33.3
Fixed in:
2.33.4
Disclosed:
Oct 31, 2023

CVE-2023-4246 on NVD →

GiveWP < 2.33.2 - Missing Authorization via handleBeforeGateway

medium
Affected:
up to 2.33.2
Fixed in:
2.33.2
Disclosed:
Oct 31, 2023

CVE-2023-47183 on NVD →

GiveWP < 2.33.4 - Cross-Site Request Forgery to Stripe Integration Deletion

medium
Affected:
up to 2.33.4
Fixed in:
2.33.4
Disclosed:
Oct 31, 2023

CVE-2023-4248 on NVD →

GiveWP < 2.33.4 - Cross-Site Request Forgery to plugin deactivation

medium
Affected:
up to 2.33.4
Fixed in:
2.33.4
Disclosed:
Oct 31, 2023

CVE-2023-4247 on NVD →

GiveWP < 2.33.4 - Cross-Site Request Forgery to plugin installation

medium
Affected:
up to 2.33.4
Fixed in:
2.33.4
Disclosed:
Oct 31, 2023

CVE-2023-4246 on NVD →

Give - Donation Plugin <= 2.33.0 - Authenticated(Give Manager+) Privilege Escalation

high

The Give - Donation Plugin plugin for WordPress is vulnerable to privilege escalation due to an insufficient capability check when updating default roles in versions up to, and including, 2.33.0. This makes it possible for authenticated attackers with Give Manager privileges to elevate their privileges to those of an a...

CVSS:
7.2
Affected:
up to 2.33.1
Fixed in:
2.33.1
Disclosed:
Aug 31, 2023

CVE-2023-41665 on NVD →

GiveWP &#8211; Donation Plugin and Fundraising Platform [give] < 2.33.1

unknown

The Give - Donation Plugin plugin for WordPress is vulnerable to privilege escalation due to an insufficient capability check when updating default roles in versions up to, and including, 2.33.0. This makes it possible for authenticated attackers with Give Manager privileges to elevate their privileges to those of an a...

Affected:
up to 2.33.1
Fixed in:
2.33.1
Disclosed:
Aug 31, 2023

Give - Donation Plugin < 2.33.1 - Authenticated(Give Manager+) Privilege Escalation

critical
Affected:
up to 2.33.1
Fixed in:
2.33.1
Disclosed:
Aug 31, 2023

CVE-2023-41665 on NVD →

GiveWP &#8211; Donation Plugin and Fundraising Platform [give] < 2.25.2

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in GiveWP GiveWP – Donation Plugin and Fundraising Platform plugin <= 2.25.1 versions.

Affected:
up to 2.25.2
Fixed in:
2.25.2
Disclosed:
Jun 15, 2023

CVE-2023-25450 on NVD →

GiveWP <= 2.25.3 - Authenticated (Admin+) PHP Object Injection

medium

The GiveWP plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.25.3 via deserialization of untrusted input via the $output['main_key'] value. This allows authenticated attackers, with administrative privileges, to inject a PHP Object that will deserialize upon a data export. N...

CVSS:
6.6
Affected:
up to 2.25.3
Fixed in:
2.26.0
Disclosed:
May 10, 2023

CVE-2023-32513 on NVD →

GiveWP &#8211; Donation Plugin and Fundraising Platform [give] < 2.25.2

unknown

[en] Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in GiveWP plugin <= 2.25.1 versions.

Affected:
up to 2.25.2
Fixed in:
2.25.2
Disclosed:
May 8, 2023

CVE-2023-23668 on NVD →

GiveWP &#8211; Donation Plugin and Fundraising Platform [give] < 2.25.3

unknown

Update the WordPress GiveWP plugin to the latest available version (at least 2.25.3). Rafie Muhammad (Patchstack) discovered and reported this Cross Site Request Forgery (CSRF) vulnerability in WordPress GiveWP Plugin. This could allow a malicious actor to force higher privileged users to execute unwanted actions under...

Affected:
up to 2.25.3
Fixed in:
2.25.3
Disclosed:
Mar 27, 2023

GiveWP <= 2.25.2 - Cross-Site Request Forgery via give_ajax_delete_payment_note

medium

The GiveWP for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.25.2. This is due to missing or incorrect nonce validation on the give_ajax_delete_payment_note function. This makes it possible for unauthenticated attackers to add donation notes via a forged request granted they...

CVSS:
5.3
Affected:
up to 2.25.2
Fixed in:
2.25.3
Disclosed:
Mar 23, 2023

GiveWP <= 2.25.2 - Cross-Site Request Forgery via give_ajax_store_payment_note

medium

The GiveWP for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.25.2. This is due to missing or incorrect nonce validation on the give_ajax_store_payment_note function. This makes it possible for unauthenticated attackers to add donation notes via a forged request granted they c...

CVSS:
5.3
Affected:
up to 2.25.2
Fixed in:
2.25.3
Disclosed:
Mar 23, 2023

GiveWP <= 2.25.2 - Cross-Site Request Forgery

medium

The GiveWP for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.25.2. This is due to missing or incorrect nonce validation on the give_donation_import_callback function. This makes it possible for unauthenticated attackers to process the import of donations via a forged request...

CVSS:
4.3
Affected:
up to 2.25.2
Fixed in:
2.25.3
Disclosed:
Mar 23, 2023

GiveWP &#8211; Donation Plugin and Fundraising Platform [give] < 2.25.3

unknown

The GiveWP for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.25.2. This is due to missing or incorrect nonce validation on the give_donation_import_callback function. This makes it possible for unauthenticated attackers to process the import of donations via a forged request...

Affected:
up to 2.25.3
Fixed in:
2.25.3
Disclosed:
Mar 23, 2023

GiveWP &#8211; Donation Plugin and Fundraising Platform [give] < 2.25.3

unknown

The GiveWP for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.25.2. This is due to missing or incorrect nonce validation on the give_ajax_delete_payment_note function. This makes it possible for unauthenticated attackers to add donation notes via a forged request granted they...

Affected:
up to 2.25.3
Fixed in:
2.25.3
Disclosed:
Mar 23, 2023

GiveWP &#8211; Donation Plugin and Fundraising Platform [give] < 2.25.3

unknown

The GiveWP for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.25.2. This is due to missing or incorrect nonce validation on the give_ajax_store_payment_note function. This makes it possible for unauthenticated attackers to add donation notes via a forged request granted they c...

Affected:
up to 2.25.3
Fixed in:
2.25.3
Disclosed:
Mar 23, 2023

GiveWP < 2.25.3 - Cross-Site Request Forgery

medium
Affected:
up to 2.25.3
Fixed in:
2.25.3
Disclosed:
Mar 23, 2023

GiveWP <= 2.25.1 - Authenticated (Author+) Stored Cross-Site Scripting

medium

The GiveWP plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.25.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with author-level access, and above, to inject arbitrary web scripts in pages that will exe...

CVSS:
6.4
Affected:
up to 2.25.1
Fixed in:
2.25.2
Disclosed:
Mar 10, 2023

CVE-2022-40211 on NVD →

GiveWP <= 2.25.1 - Authenticated (Contributor+) Arbitrary Content Deletion

medium

The GiveWP plugin for WordPress is vulnerable to Improper Authorization in versions up to, and including, 2.25.1. This makes it possible for authenticated attackers with contributor-level permissions to delete content from a vulnerable site.

CVSS:
5.4
Affected:
up to 2.25.1
Fixed in:
2.25.2
Disclosed:
Mar 10, 2023

CVE-2023-23672 on NVD →

GiveWP < 2.25.2 - Cross-Site Request Forgery

medium
Affected:
up to 2.25.2
Fixed in:
2.25.2
Disclosed:
Mar 10, 2023

CVE-2023-25450 on NVD →

GiveWP < 2.25.2 - Author+ Stored Cross-Site Scripting

medium
Affected:
up to 2.25.2
Fixed in:
2.25.2
Disclosed:
Mar 10, 2023

CVE-2022-40211 on NVD →

GiveWP < 2.25.2 - Contributor+ Arbitrary Content Deletion

unknown
Affected:
up to 2.25.2
Fixed in:
2.25.2
Disclosed:
Mar 10, 2023

CVE-2023-23672 on NVD →

GiveWP <= 2.25.1 - Unauthenticated CSV Injection

high

The GiveWP plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, 2.25.1 via the 'print_csv_rows' function used in exporting CSV files. This allows attackers to embed untrusted input into exported CSV files, which can result in code execution when these files are downloaded and opened on...

CVSS:
8.3
Affected:
up to 2.25.1
Fixed in:
2.25.2
Disclosed:
Mar 8, 2023

CVE-2023-22719 on NVD →

GiveWP <= 2.25.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via give_form_grid shortcode

medium

The GiveWP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'give_form_grid' shortcode in versions up to, and including, 2.25.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and a...

CVSS:
6.4
Affected:
up to 2.25.1
Fixed in:
2.25.2
Disclosed:
Mar 8, 2023

CVE-2023-23668 on NVD →

GiveWP <= 2.25.1 - Cross-Site Request Forgery to Cross-Site Scripting via render_dropdown

medium

The GiveWP plugin is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.25.1. This is due to missing or incorrect nonce validation on the 'render_dropdown' AJAX function. This makes it possible for unauthenticated attackers to execute JavaScript in the browser of an administrator via forged re...

CVSS:
6.1
Affected:
up to 2.25.1
Fixed in:
2.25.2
Disclosed:
Mar 8, 2023

GiveWP <= 2.25.1 - Cross-Site Request Forgery via process_bulk_action

medium

The GiveWP plugin is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.25.1. This is due to missing or incorrect nonce validation on the 'process_bulk_action' AJAX function. This makes it possible for unauthenticated attackers to perform various bulk actions including deleting content via for...

CVSS:
5.4
Affected:
up to 2.25.1
Fixed in:
2.25.2
Disclosed:
Mar 8, 2023

GiveWP <= 2.25.1 - Cross-Site Request Forgery via give_cache_flush

medium

The GiveWP plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.25.1. This is due to missing or incorrect nonce validation on the 'give_cache_flush' AJAX function. This makes it possible for unauthenticated attackers to flush the GiveWP cache via forged request granted th...

CVSS:
4.3
Affected:
up to 2.25.1
Fixed in:
2.25.2
Disclosed:
Mar 8, 2023

CVE-2023-25450 on NVD →

GiveWP <= 2.25.1 - Cross-Site Request Forgery via save

medium

The GiveWP plugin is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.25.1. This is due to missing or incorrect nonce validation on the 'save' AJAX function. This makes it possible for unauthenticated attackers to import donations via forged request granted a CSV file containing those donati...

CVSS:
4.3
Affected:
up to 2.25.1
Fixed in:
2.25.2
Disclosed:
Mar 8, 2023

GiveWP <= 2.25.1 - Authenticated (Admin+) Server-Side Request Forgery via give_get_content_by_ajax_handler

medium

The GiveWP plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including, 2.25.1 via the 'give_get_content_by_ajax_handler'. This can allow authenticated attackers with administrator-level privileges to make web requests to arbitrary locations originating from the web application an...

CVSS:
4.1
Affected:
up to 2.25.1
Fixed in:
2.25.2
Disclosed:
Mar 8, 2023

CVE-2022-40312 on NVD →

GiveWP &#8211; Donation Plugin and Fundraising Platform [give] < 2.25.2

unknown

The GiveWP plugin is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.25.1. This is due to missing or incorrect nonce validation on the 'process_bulk_action' AJAX function. This makes it possible for unauthenticated attackers to perform various bulk actions including deleting content via for...

Affected:
up to 2.25.2
Fixed in:
2.25.2
Disclosed:
Mar 8, 2023

GiveWP &#8211; Donation Plugin and Fundraising Platform [give] < 2.25.2

unknown

The GiveWP plugin is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.25.1. This is due to missing or incorrect nonce validation on the 'render_dropdown' AJAX function. This makes it possible for unauthenticated attackers to execute JavaScript in the browser of an administrator via forged re...

Affected:
up to 2.25.2
Fixed in:
2.25.2
Disclosed:
Mar 8, 2023

GiveWP &#8211; Donation Plugin and Fundraising Platform [give] < 2.25.2

unknown

The GiveWP plugin is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.25.1. This is due to missing or incorrect nonce validation on the 'save' AJAX function. This makes it possible for unauthenticated attackers to import donations via forged request granted a CSV file containing those donati...

Affected:
up to 2.25.2
Fixed in:
2.25.2
Disclosed:
Mar 8, 2023

GiveWP &#8211; Donation Plugin and Fundraising Platform [give] < 2.25.2

unknown

The GiveWP plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including, 2.25.1 via the 'give_get_content_by_ajax_handler'. This can allow authenticated attackers with administrator-level privileges to make web requests to arbitrary locations originating from the web application an...

Affected:
up to 2.25.2
Fixed in:
2.25.2
Disclosed:
Mar 8, 2023

GiveWP &#8211; Donation Plugin and Fundraising Platform [give] < 2.25.2

unknown

The GiveWP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'give_form_grid' shortcode in versions up to, and including, 2.25.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and a...

Affected:
up to 2.25.2
Fixed in:
2.25.2
Disclosed:
Mar 8, 2023

GiveWP &#8211; Donation Plugin and Fundraising Platform [give] < 2.25.2

unknown

The GiveWP plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, 2.25.1 via the 'print_csv_rows' function used in exporting CSV files. This allows attackers to embed untrusted input into exported CSV files, which can result in code execution when these files are downloaded and opened on...

Affected:
up to 2.25.2
Fixed in:
2.25.2
Disclosed:
Mar 8, 2023

GiveWP &#8211; Donation Plugin and Fundraising Platform [give] < 2.25.2

unknown

The GiveWP plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.25.1. This is due to missing or incorrect nonce validation on the 'give_cache_flush' AJAX function. This makes it possible for unauthenticated attackers to flush the GiveWP cache via forged request granted th...

Affected:
up to 2.25.2
Fixed in:
2.25.2
Disclosed:
Mar 8, 2023

GiveWP < 2.25.2 - Admin+ Server-Side Request Forgery

medium
Affected:
up to 2.25.2
Fixed in:
2.25.2
Disclosed:
Mar 8, 2023

CVE-2022-40312 on NVD →

GiveWP < 2.25.2 - Contributor+ Stored XSS

medium
Affected:
up to 2.25.2
Fixed in:
2.25.2
Disclosed:
Mar 8, 2023

CVE-2023-23668 on NVD →

GiveWP &#8211; Donation Plugin and Fundraising Platform [give] < 2.24

unknown

[en] The GiveWP WordPress plugin before 2.24.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

Affected:
up to 2.24
Fixed in:
2.24
Disclosed:
Feb 13, 2023

CVE-2022-4448 on NVD →

GiveWP <= 2.23.2 - Unauthenticated SQL Injection

critical

The GiveWP plugin for WordPress is vulnerable to SQL Injection versions up to, and including, 2.23.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into alrea...

CVSS:
9.8
Affected:
up to 2.23.2
Fixed in:
2.24
Disclosed:
Jan 19, 2023

CVE-2023-0224 on NVD →

GiveWP <= 2.23.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

medium

The GiveWP for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in versions up to, and including, 2.23.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor level and above permissi...

CVSS:
6.4
Affected:
up to 2.23.2
Fixed in:
2.24
Disclosed:
Jan 19, 2023

CVE-2022-4448 on NVD →

GiveWP &#8211; Donation Plugin and Fundraising Platform [give] < 2.24

unknown

The GiveWP plugin for WordPress is vulnerable to SQL Injection versions up to, and including, 2.23.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into alrea...

Affected:
up to 2.24
Fixed in:
2.24
Disclosed:
Jan 19, 2023

GiveWP < 2.24.0 - Contributor+ Stored XSS

medium
Affected:
up to 2.24.0
Fixed in:
2.24.0
Disclosed:
Jan 19, 2023

CVE-2022-4448 on NVD →

GiveWP < 2.24.1 - Unauthenticated SQLi

unknown
Affected:
up to 2.24.1
Fixed in:
2.24.1
Disclosed:
Jan 19, 2023

CVE-2023-0224 on NVD →

GiveWP &#8211; Donation Plugin and Fundraising Platform [give] < 2.21.3

unknown

[en] The GiveWP WordPress plugin before 2.21.3 does not have CSRF in place when exporting data, and does not validate the exporting parameters such as dates, which could allow attackers to make a logged in admin DoS the web server via a CSRF attack as the plugin will try to retrieve data from the database many times wh...

Affected:
up to 2.21.3
Fixed in:
2.21.3
Disclosed:
Aug 1, 2022

CVE-2022-2260 on NVD →

GiveWP &#8211; Donation Plugin and Fundraising Platform [give] < 2.21.3

unknown

[en] The GiveWP WordPress plugin before 2.21.3 does not properly sanitise and escape the currency settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks when the unfiltered_html capability is disallowed (for example in multisite setup)

Affected:
up to 2.21.3
Fixed in:
2.21.3
Disclosed:
Aug 1, 2022

CVE-2022-2215 on NVD →

GiveWP &#8211; Donation Plugin and Fundraising Platform [give] < 2.21.3

unknown

[en] Authenticated (custom plugin role) Arbitrary File Read via Export function vulnerability in GiveWP's GiveWP plugin <= 2.20.2 at WordPress.

Affected:
up to 2.21.3
Fixed in:
2.21.3
Disclosed:
Jul 21, 2022

CVE-2022-31475 on NVD →

GiveWP &#8211; Donation Plugin and Fundraising Platform [give] < 2.21.0

unknown

[en] Authenticated Arbitrary File Creation via Export function vulnerability in GiveWP's GiveWP plugin <= 2.20.2 at WordPress.

Affected:
up to 2.21.0
Fixed in:
2.21.0
Disclosed:
Jul 21, 2022

CVE-2022-28700 on NVD →

GiveWP &#8211; Donation Plugin and Fundraising Platform [give] < 2.21.0

unknown

[en] The GiveWP plugin for WordPress is vulnerable to Sensitive Information Disclosure in versions up to, and including, 2.20.2 via the /donor-wall REST-API endpoint which provides unauthenticated users with donor information even when the donor wall is not enabled. This functionality has been completely removed in ver...

Affected:
up to 2.21.0
Fixed in:
2.21.0
Disclosed:
Jul 18, 2022

CVE-2022-2117 on NVD →

GiveWP <= 2.20.2 - Authenticated Arbitrary File Read

medium

Authenticated (custom plugin role) Arbitrary File Read via Export function vulnerability in GiveWP's GiveWP plugin <= 2.20.2 at WordPress.

CVSS:
4.9
Affected:
up to 2.20.2
Fixed in:
2.21.0
Disclosed:
Jul 12, 2022

CVE-2022-31475 on NVD →

GiveWP <= 2.20.2 - Authenticated Arbitrary File Creation

medium

Authenticated Arbitrary File Creation via Export function vulnerability in GiveWP's GiveWP plugin <= 2.20.2 at WordPress.

CVSS:
5.5
Affected:
up to 2.20.2
Fixed in:
2.21.0
Disclosed:
Jul 12, 2022

CVE-2022-28700 on NVD →

GiveWP < 2.21.0 - Manager+ Arbitrary File Creation via Export

unknown
Affected:
up to 2.21.0
Fixed in:
2.21.0
Disclosed:
Jul 12, 2022

CVE-2022-28700 on NVD →

GiveWP < 2.21.0 - Manager+ Arbitrary File Access via Export

unknown
Affected:
up to 2.21.0
Fixed in:
2.21.0
Disclosed:
Jul 12, 2022

CVE-2022-31475 on NVD →

GiveWP <= 2.21.2 - Authenticated (Admin+) Stored Cross-Site Scripting

medium

The GiveWP WordPress plugin before 2.21.3 does not properly sanitise and escape the currency settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks when the unfiltered_html capability is disallowed (for example in multisite setup)

CVSS:
5.5
Affected:
up to 2.21.2
Fixed in:
2.21.3
Disclosed:
Jul 11, 2022

CVE-2022-2215 on NVD →

GiveWP < 2.21.3 - DoS via CSRF

medium
Affected:
up to 2.21.3
Fixed in:
2.21.3
Disclosed:
Jul 11, 2022

CVE-2022-2260 on NVD →

GiveWP < 2.21.3 - Admin+ Stored Cross-Site Scripting

medium
Affected:
up to 2.21.3
Fixed in:
2.21.3
Disclosed:
Jul 11, 2022

CVE-2022-2215 on NVD →

GiveWP – Donation Plugin and Fundraising Platform <= 2.21.2 - Cross-Site Request Forgery

medium

The GiveWP plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.21.2. This is due to missing or incorrect nonce validation on the can_export function. This makes it possible for unauthenticated attackers to trigger report exports via forged request granted they can trick...

CVSS:
4.3
Affected:
up to 2.21.2
Fixed in:
2.21.3
Disclosed:
Jul 8, 2022

CVE-2022-2260 on NVD →

GiveWP &#8211; Donation Plugin and Fundraising Platform [give] < 2.21.0

unknown

Reflected Cross-Site Scripting (XSS) vulnerability discovered by WPScanTeam in WordPress GiveWP plugin (versions <= 2.20.2). Update the WordPress GiveWP plugin to the latest available version (at least 2.21.0).

Affected:
up to 2.21.0
Fixed in:
2.21.0
Disclosed:
Jun 20, 2022

Give < 2.21.0 - Reflected Cross-Site Scripting

medium
Affected:
up to 2.21.0
Fixed in:
2.21.0
Disclosed:
Jun 20, 2022

GiveWP – Donation Plugin and Fundraising Platform <= 2.20.2 - Sensitive Information Disclosure

medium

The GiveWP plugin for WordPress is vulnerable to Sensitive Information Disclosure in versions up to, and including, 2.20.2 via the /donor-wall REST-API endpoint which provides unauthenticated users with donor information even when the donor wall is not enabled. This functionality has been completely removed in version...

CVSS:
5.3
Affected:
up to 2.20.2
Fixed in:
2.21.0
Disclosed:
Jun 17, 2022

CVE-2022-2117 on NVD →

GiveWP < 2.21.0 - Donor Information Disclosure

medium
Affected:
up to 2.21.0
Fixed in:
2.21.0
Disclosed:
Jun 17, 2022

CVE-2022-2117 on NVD →

GiveWP &#8211; Donation Plugin and Fundraising Platform [give] < 2.17.3

unknown

[en] The GiveWP WordPress plugin before 2.17.3 does not escape the json parameter before outputting it back in an attribute in the Import admin dashboard, leading to a Reflected Cross-Site Scripting

Affected:
up to 2.17.3
Fixed in:
2.17.3
Disclosed:
Feb 21, 2022

CVE-2022-0252 on NVD →

GiveWP &#8211; Donation Plugin and Fundraising Platform [give] < 2.17.3

unknown

[en] The GiveWP WordPress plugin before 2.17.3 does not sanitise and escape the form_id parameter before outputting it back in the response of an unauthenticated request via the give_checkout_login AJAX action, leading to a Reflected Cross-Site Scripting

Affected:
up to 2.17.3
Fixed in:
2.17.3
Disclosed:
Feb 21, 2022

CVE-2021-25099 on NVD →

GiveWP &#8211; Donation Plugin and Fundraising Platform [give] < 2.17.3

unknown

[en] The GiveWP WordPress plugin before 2.17.3 does not escape the s parameter before outputting it back in an attribute in the Donation Forms dashboard, leading to a Reflected Cross-Site Scripting

Affected:
up to 2.17.3
Fixed in:
2.17.3
Disclosed:
Feb 21, 2022

CVE-2021-25100 on NVD →

GiveWP <= 2.17.2 - Reflected Cross-Site Scripting

medium

The GiveWP WordPress plugin before 2.17.3 does not escape the s parameter before outputting it back in an attribute in the Donation Forms dashboard, leading to a Reflected Cross-Site Scripting

CVSS:
6.1
Affected:
up to 2.17.3
Fixed in:
2.17.3
Disclosed:
Jan 18, 2022

CVE-2021-25100 on NVD →

GiveWP <= 2.17.2 - Reflected Cross-Site Scripting

medium

The GiveWP WordPress plugin before 2.17.3 does not sanitise and escape the form_id parameter before outputting it back in the response of an unauthenticated request via the give_checkout_login AJAX action, leading to a Reflected Cross-Site Scripting

CVSS:
6.1
Affected:
up to 2.17.3
Fixed in:
2.17.3
Disclosed:
Jan 18, 2022

CVE-2021-25099 on NVD →

GiveWP <= 2.17.2 - Reflected Cross-Site Scripting via Import Tool

medium

The GiveWP WordPress plugin before 2.17.3 does not escape the json parameter before outputting it back in an attribute in the Import admin dashboard, leading to a Reflected Cross-Site Scripting

CVSS:
4.8
Affected:
up to 2.17.3
Fixed in:
2.17.3
Disclosed:
Jan 18, 2022

CVE-2022-0252 on NVD →

Give < 2.17.3 - Reflected Cross-Site Scripting via Import Tool

medium
Affected:
up to 2.17.3
Fixed in:
2.17.3
Disclosed:
Jan 18, 2022

CVE-2022-0252 on NVD →

Give < 2.17.3 - Reflected Cross-Site Scripting via Donation Forms Dashboard

medium
Affected:
up to 2.17.3
Fixed in:
2.17.3
Disclosed:
Jan 18, 2022

CVE-2021-25100 on NVD →

Give < 2.17.3 - Unauthenticated Reflected Cross-Site Scripting

medium
Affected:
up to 2.17.3
Fixed in:
2.17.3
Disclosed:
Jan 18, 2022

CVE-2021-25099 on NVD →

GiveWP &#8211; Donation Plugin and Fundraising Platform [give] < 2.21.3

unknown

[en] The GiveWP – Donation Plugin and Fundraising Platform WordPress plugin before 2.12.0 did not escape the Donation Level setting of its Donation Forms, allowing high privilege users to use Cross-Site Scripting payloads in them.

Affected:
up to 2.21.3
Fixed in:
2.21.3
Disclosed:
Aug 23, 2021

CVE-2021-24524 on NVD →

GiveWP <= 2.11.3 - Authenticated Stored Cross-Site Scripting

medium

The GiveWP – Donation Plugin and Fundraising Platform WordPress plugin before 2.12.0 did not escape the Donation Level setting of its Donation Forms, allowing high privilege users to use Cross-Site Scripting payloads in them.

CVSS:
4.8
Affected:
up to 2.12.0
Fixed in:
2.12.0
Disclosed:
Jul 26, 2021

CVE-2021-24524 on NVD →

GiveWP < 2.12.0 - Admin+ Stored XSS

medium
Affected:
up to 2.12.0
Fixed in:
2.12.0
Disclosed:
Jul 26, 2021

CVE-2021-24524 on NVD →

GiveWP &#8211; Donation Plugin and Fundraising Platform [give] < 2.10.4

unknown

[en] The GiveWP – Donation Plugin and Fundraising Platform WordPress plugin before 2.10.4 did not sanitise or escape the Background Image field of its Stripe Checkout Setting and Logo field in its Email settings, leading to authenticated (admin+) Stored XSS issues.

Affected:
up to 2.10.4
Fixed in:
2.10.4
Disclosed:
May 17, 2021

CVE-2021-24315 on NVD →

GiveWP <= 2.10.3 - Authenticated Stored Cross-Site Scripting

medium

The GiveWP – Donation Plugin and Fundraising Platform WordPress plugin before 2.10.4 did not sanitise or escape the Background Image field of its Stripe Checkout Setting and Logo field in its Email settings, leading to authenticated (admin+) Stored XSS issues.

CVSS:
4.8
Affected:
up to 2.10.4
Fixed in:
2.10.4
Disclosed:
Apr 30, 2021

CVE-2021-24315 on NVD →

Give WP < 2.10.4 - Authenticated Stored Cross-Site Scripting (XSS)

medium
Affected:
up to 2.10.4
Fixed in:
2.10.4
Disclosed:
Apr 30, 2021

CVE-2021-24315 on NVD →

GiveWP &#8211; Donation Plugin and Fundraising Platform [give] < 2.10.2

unknown

Authenticated Persistent Cross-Site Scripting (XSS) vulnerability discovered by m0ze (Patchstack Red Team) in WordPress GiveWP plugin (versions <= 2.10.1).

Affected:
up to 2.10.2
Fixed in:
2.10.2
Disclosed:
Apr 21, 2021

GiveWP &#8211; Donation Plugin and Fundraising Platform [give] < 2.10.0

unknown

[en] The GiveWP – Donation Plugin and Fundraising Platform WordPress plugin before 2.10.0 was affected by a reflected Cross-Site Scripting vulnerability inside of the administration panel, via the 's' GET parameter on the Donors page.

Affected:
up to 2.10.0
Fixed in:
2.10.0
Disclosed:
Apr 12, 2021

CVE-2021-24213 on NVD →

GiveWP 2.4.0 - 2.9.7 - Reflected Cross Site Scripting

medium

The GiveWP – Donation Plugin and Fundraising Platform WordPress plugin before 2.10.0 was affected by a reflected Cross-Site Scripting vulnerability inside of the administration panel, via the 's' GET parameter on the Donors page.

CVSS:
6.1
Affected:
2.4.0 – 2.10.0
Fixed in:
2.10.0
Disclosed:
Mar 23, 2021

CVE-2021-24213 on NVD →

GiveWP &#8211; Donation Plugin and Fundraising Platform [give] < 2.10.0

unknown

Reflected Cross-Site Scripting (XSS) vulnerability discovered by Austin Bentley in WordPress GiveWP plugin (versions <= 2.9.7).

Affected:
up to 2.10.0
Fixed in:
2.10.0
Disclosed:
Mar 23, 2021

GiveWP < 2.10.0 - Reflected Cross Site Scripting (XSS)

medium
Affected:
2.4.0 – 2.10.0
Fixed in:
2.10.0
Disclosed:
Mar 23, 2021

CVE-2021-24213 on NVD →

GiveWP &#8211; Donation Plugin and Fundraising Platform [give] < 2.5.10

unknown

[en] The includes/gateways/stripe/includes/admin/admin-actions.php in GiveWP plugin through 2.5.9 for WordPress allows unauthenticated settings change.

Affected:
up to 2.5.10
Fixed in:
2.5.10
Disclosed:
Aug 31, 2020

CVE-2020-20627 on NVD →

GiveWP &#8211; Donation Plugin and Fundraising Platform [give] < 2.5.5

unknown

[en] A flaw in Give before 2.5.5, a WordPress plugin, allowed unauthenticated users to bypass API authentication methods and access personally identifiable user information (PII) including names, addresses, IP addresses, and email addresses. Once an API key has been set to any meta key value from the wp_usermeta table,...

Affected:
up to 2.5.5
Fixed in:
2.5.5
Disclosed:
Jan 8, 2020

CVE-2019-20360 on NVD →

GiveWP <= 2.5.9 - Missing Authorization to Settings Update

medium

The includes/gateways/stripe/includes/admin/admin-actions.php in GiveWP plugin through 2.5.9 for WordPress allows unauthenticated settings change.

CVSS:
5.3
Affected:
up to 2.5.10
Fixed in:
2.5.10
Disclosed:
Oct 30, 2019

CVE-2020-20627 on NVD →

Give WP < 2.5.10 - Multiple Issues

unknown
Affected:
up to 2.5.10
Fixed in:
2.5.10
Disclosed:
Oct 30, 2019

CVE-2020-20627 on NVD →

GiveWP <= 2.5.4 - Authorization Bypass

high

A flaw in Give before 2.5.5, a WordPress plugin, allowed unauthenticated users to bypass API authentication methods and access personally identifiable user information (PII) including names, addresses, IP addresses, and email addresses. Once an API key has been set to any meta key value from the wp_usermeta table, and...

CVSS:
7.5
Affected:
up to 2.5.4
Fixed in:
2.5.5
Disclosed:
Sep 26, 2019

CVE-2019-20360 on NVD →

GiveWP &#8211; Donation Plugin and Fundraising Platform [give] < 2.5.5

unknown

The weakness allows unauthenticated users to bypass API authentication methods and potentially access personally identifiable user information (PII) like names, addresses, IP addresses, and email addresses.

Affected:
up to 2.5.5
Fixed in:
2.5.5
Disclosed:
Sep 26, 2019

GiveWp < 2.5.5 - Authentication Bypass

critical
Affected:
up to 2.5.5
Fixed in:
2.5.5
Disclosed:
Sep 26, 2019

CVE-2019-20360 on NVD →

GiveWP &#8211; Donation Plugin and Fundraising Platform [give] < 2.4.7

unknown

[en] The give plugin before 2.4.7 for WordPress has XSS via a donor name.

Affected:
up to 2.4.7
Fixed in:
2.4.7
Disclosed:
Aug 22, 2019

CVE-2019-15317 on NVD →

GiveWP &#8211; Donation Plugin and Fundraising Platform [give] < 2.5.1

unknown

[en] A SQL injection vulnerability exists in the Impress GiveWP Give plugin through 2.5.0 for WordPress. Successful exploitation of this vulnerability would allow a remote attacker to execute arbitrary SQL commands on the affected system via includes/payments/class-payments-query.php.

Affected:
up to 2.5.1
Fixed in:
2.5.1
Disclosed:
Aug 15, 2019

CVE-2019-13578 on NVD →

GiveWP - Donation Plugin and Fundraising Platform <= 2.5.0 - SQL Injection

critical

A SQL injection vulnerability exists in the Impress GiveWP Give plugin through 2.5.0 for WordPress. Successful exploitation of this vulnerability would allow a remote attacker to execute arbitrary SQL commands on the affected system via includes/payments/class-payments-query.php.

CVSS:
9.8
Affected:
up to 2.5.0
Fixed in:
2.5.1
Disclosed:
Aug 12, 2019

CVE-2019-13578 on NVD →

GiveWP &#8211; Donation Plugin and Fundraising Platform [give] < 2.5.1

unknown

SQL Injection (SQLi) vulnerability found by Tin Duong (Fortinet FortiGuard Labs) in WordPress Give plugin (version <= 2.5.0).

Affected:
up to 2.5.1
Fixed in:
2.5.1
Disclosed:
Aug 12, 2019

Give <= 2.5.0 - SQL Injection

critical
Affected:
up to 2.5.1
Fixed in:
2.5.1
Disclosed:
Aug 12, 2019

CVE-2019-13578 on NVD →

GiveWP <= 2.4.6 - Cross-Site Scripting

medium

The give plugin before 2.4.7 for WordPress has XSS via a donor name.

CVSS:
5.4
Affected:
up to 2.4.7
Fixed in:
2.4.7
Disclosed:
May 15, 2019

CVE-2019-15317 on NVD →

GiveWP &#8211; Donation Plugin and Fundraising Platform [give] < 2.3.1

unknown

[en] The "Donation Plugin and Fundraising Platform" plugin before 2.3.1 for WordPress has wp-admin/edit.php csv XSS.

Affected:
up to 2.3.1
Fixed in:
2.3.1
Disclosed:
Mar 21, 2019

CVE-2019-9909 on NVD →

GiveWP <= 2.3.0 - Cross-Site Scripting

medium

The "Donation Plugin and Fundraising Platform" plugin before 2.3.1 for WordPress has wp-admin/edit.php csv XSS.

CVSS:
6.1
Affected:
up to 2.3.1
Fixed in:
2.3.1
Disclosed:
Feb 5, 2019

CVE-2019-9909 on NVD →

Give <= 2.3.0 - Cross-Site Scripting (XSS)

medium
Affected:
up to 2.3.1
Fixed in:
2.3.1
Disclosed:
Feb 5, 2019

CVE-2019-9909 on NVD →

GiveWP – Donation Plugin and Fundraising Platform < 0.8.5 - Reflected Cross-Site Scripting

medium

The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Cross-Site Scripting in versions before 0.8.5 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser.

CVSS:
6.1
Affected:
up to 0.8.5
Fixed in:
0.8.5
Disclosed:
Apr 20, 2015

GiveWP &#8211; Donation Plugin and Fundraising Platform [give] < 0.8.5

unknown

Because of this vulnerability, the attackers can inject arbitrary web script or HTML. Update the plugin.

Affected:
up to 0.8.5
Fixed in:
0.8.5
Disclosed:
Apr 20, 2015

GiveWP &#8211; Donation Plugin and Fundraising Platform [give] < 0.8.5

unknown

The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Cross-Site Scripting in versions before 0.8.5 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser.

Affected:
up to 0.8.5
Fixed in:
0.8.5
Disclosed:
Apr 20, 2015

Give - Cross-Site Scripting (XSS)

medium
Affected:
up to 0.8.5
Fixed in:
0.8.5
Disclosed:
Apr 20, 2015

GiveWP &#8211; Donation Plugin and Fundraising Platform [give] < 2.21.0

unknown

The plugin does not escape some URLs before outputting them back in attributes, leading to Reflected Cross-Site Scripting

Affected:
up to 2.21.0
Fixed in:
2.21.0

GiveWP &#8211; Donation Plugin and Fundraising Platform [give] < 0.8.5

unknown

The GiveWP &ndash; Donation Plugin and Fundraising Platform WordPress plugin was affected by a Cross-Site Scripting (XSS) security vulnerability.

Affected:
up to 0.8.5
Fixed in:
0.8.5

GiveWP &#8211; Donation Plugin and Fundraising Platform [give] < 2.25.3

unknown

The plugin does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks.

Affected:
up to 2.25.3
Fixed in:
2.25.3

GiveWP &#8211; Donation Plugin and Fundraising Platform [give] < 3.20.0

unknown
Affected:
up to 3.20.0
Fixed in:
3.20.0

CVE-2025-0912 on NVD →

GiveWP &#8211; Donation Plugin and Fundraising Platform [give] < 3.22.1

unknown
Affected:
up to 3.22.1
Fixed in:
3.22.1

CVE-2025-2025 on NVD →

GiveWP &#8211; Donation Plugin and Fundraising Platform [give] < 3.22.2

unknown
Affected:
up to 3.22.2
Fixed in:
3.22.2

CVE-2025-2331 on NVD →

GiveWP &#8211; Donation Plugin and Fundraising Platform [give] < 4.3.1

unknown
Affected:
up to 4.3.1
Fixed in:
4.3.1

CVE-2025-4571 on NVD →

GiveWP &#8211; Donation Plugin and Fundraising Platform [give] < 4.6.0

unknown
Affected:
up to 4.6.0
Fixed in:
4.6.0

CVE-2025-7205 on NVD →

GiveWP &#8211; Donation Plugin and Fundraising Platform [give] < 4.6.1

unknown
Affected:
up to 4.6.1
Fixed in:
4.6.1

CVE-2025-8620 on NVD →

GiveWP &#8211; Donation Plugin and Fundraising Platform [give] < 4.6.1

unknown
Affected:
up to 4.6.1
Fixed in:
4.6.1

CVE-2025-7221 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database