GiveWP – Donation Plugin and Fundraising Platform
give · plugin
Known security vulnerabilities for GiveWP – Donation Plugin and Fundraising Platform. Find out in seconds which version runs on your site with WP Lens.
68 known vulnerabilities
12 critical · 42 exploitable without logging in · 5 with public exploit code · latest Sep 30, 2026
Listed on wordpress.org · latest 4.18.0 · last updated Oct 1, 2026 · 100K+ installs
wordpress.org status checked on Oct 2, 2026
Vulnerabilities
- Critical 10.0
CVE-2026-82222unauthenticated≤ 4.16.7.1
WordPress GiveWP plugin <= 4.16.7.1 - Remote Code Execution (RCE) vulnerability
- Critical 9.8
CVE-2025-0912unauthenticated≤ 3.19.4
GiveWP – Donation Plugin and Fundraising Platform <= 3.19.4 - Unauthenticated PHP Object Injection
- Critical 9.8
CVE-2025-22777unauthenticated≤ 3.19.3
WordPress GiveWP Plugin <= 3.19.3 - PHP Object Injection vulnerability
- Critical 9.8
CVE-2024-12877unauthenticated≤ 3.19.2
GiveWP – Donation Plugin and Fundraising Platform <= 3.19.2 - Unauthenticated PHP Object Injection
- Critical 9.8
CVE-2023-47183unauthenticated≤ 2.33.1
WordPress GiveWP plugin <= 2.33.1 - Broken Access Control vulnerability
- Critical 9.8
CVE-2024-9634unauthenticated≤ 3.16.3
GiveWP – Donation Plugin and Fundraising Platform <= 3.16.3 - Unauthenticated PHP Object Injection to Remote Code Execution
- Critical 9.8
CVE-2024-8353unauthenticated≤ 3.16.1
GiveWP – Donation Plugin and Fundraising Platform <= 3.16.1 - Unauthenticated PHP Object Injection
- Critical 9.8
CVE-2024-5932unauthenticated≤ 3.14.1
GiveWP – Donation Plugin and Fundraising Platform <= 3.14.1 - Unauthenticated PHP Object Injection to Remote Code Execution
- Critical 9.8
CVE-2024-37099unauthenticated≤ 3.14.1
WordPress GiveWP plugin <= 3.14.1 - Unauthenticated PHP Object Injection vulnerability
- Critical 9.8
CVE-2023-32513unauthenticated · needs a click≤ 2.25.3
WordPress GiveWP Plugin <= 2.25.3 is vulnerable to PHP Object Injection
- Critical 9.8
CVE-2023-22719unauthenticated · needs a click≤ 2.25.1
WordPress GiveWP Plugin <= 2.25.1 is vulnerable to CSV Injection
- Critical 9.1
CVE-2026-97196unauthenticated≤ 4.16.9
WordPress GiveWP plugin <= 4.16.9 - Broken Authentication vulnerability
- High 8.8
CVE-2024-47315unauthenticated · needs a click≤ 3.15.1
WordPress GiveWP – Donation Plugin and Fundraising Platform plugin <= 3.15.1 - Cross Site Request Forgery (CSRF) vulnerability
- High 8.8
CVE-2023-25450unauthenticated · needs a click≤ 2.25.1
WordPress GiveWP Plugin <= 2.25.1 is vulnerable to Cross Site Request Forgery (CSRF)
- High 8.8
CVE-2023-41665login required≤ 2.33.0
WordPress GiveWP plugin <= 2.33.0 - GiveWP Manager+ Privilege Escalation vulnerability
- High 7.5
CVE-2025-2025unauthenticated≤ 3.22.0
Give <= 3.22.0 - Missing Authorization to Unauthenticated Arbitrary Earning Reports Disclosure via give_reports_earnings Function
- High 7.2
CVE-2024-9130high privilege≤ 3.16.1
GiveWP – Donation Plugin and Fundraising Platform <= 3.16.1 - Authenticated (GiveWP Manager+) SQL Injection via order Parameter
- High 7.2
CVE-2024-30229high privilege≤ 3.4.2
WordPress Give plugin <= 3.4.2 - PHP Object Injection vulnerability
- High 7.2
CVE-2022-28700high privilege≤ 2.20.2
WordPress GiveWP plugin <= 2.20.2 - Authenticated Arbitrary File Creation via Export function vulnerability
- High 7.1
CVE-2026-96830unauthenticated · needs a click≤ 4.16.9
WordPress GiveWP plugin <= 4.16.9 - Cross Site Scripting (XSS) vulnerability
- High 7.1
CVE-2026-66690unauthenticated · needs a click≤ 4.16.5
WordPress GiveWP plugin <= 4.16.5 - Cross Site Scripting (XSS) vulnerability
- High 7.1
CVE-2026-65441unauthenticated · needs a click≤ 4.16.3
WordPress GiveWP plugin <= 4.16.3 - Cross Site Scripting (XSS) vulnerability
- High 7.1
CVE-2026-34900unauthenticated · needs a click≤ 4.14.2
WordPress GiveWP plugin <= 4.14.2 - Reflected Cross Site Scripting (XSS) vulnerability
- High 7.1
CVE-2026-42678unauthenticated · needs a click≤ 4.14.5
WordPress GiveWP plugin <= 4.14.5 - Cross Site Scripting (XSS) vulnerability
- Medium 6.5
CVE-2026-73352unauthenticated≤ 4.16.5.1
WordPress GiveWP plugin <= 4.16.5.1 - Broken Access Control vulnerability
- Medium 6.5
CVE-2026-73348unauthenticated→ 4.16.6
WordPress GiveWP plugin < 4.16.6 - Broken Access Control vulnerability
- Medium 6.5
CVE-2025-11227unauthenticated≤ 4.10.0
GiveWP – Donation Plugin and Fundraising Platform <= 4.10.0 - Missing Authorization to Unauthenticated Forms and Campaigns Disclosure
- Medium 6.5
CVE-2026-96834subscriber+≤ 4.16.9
WordPress GiveWP plugin <= 4.16.9 - Sensitive Data Exposure vulnerability
- Medium 6.5
CVE-2026-73357login required→ 4.16.6
WordPress GiveWP plugin < 4.16.6 - Cross Site Scripting (XSS) vulnerability
- Medium 6.5
CVE-2025-2331subscriber+≤ 3.22.1
GiveWP – Donation Plugin and Fundraising Platform <= 3.22.1 - Authenticated (Subscriber+) Sensitive Information Exposure
- Medium 6.5
CVE-2022-40312high privilege≤ 2.25.1
WordPress GiveWP Plugin <= 2.25.1 is vulnerable to Server Side Request Forgery (SSRF)
- Medium 6.4
CVE-2026-14987login required≤ 4.16.3
GiveWP <= 4.16.3 - Authenticated (Give Worker+) Stored Cross-Site Scripting via 'twitter_message' Sequoia Template Setting
- Medium 6.4
CVE-2026-13704login required≤ 4.16.1
GiveWP <= 4.16.1 - Authenticated (Give Worker+) Stored Cross-Site Scripting via Sequioa Form
- Medium 6.4
CVE-2026-5510contributor+≤ 4.14.4
GiveWP <= 4.14.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes
- Medium 6.4
CVE-2026-13246author+≤ 4.16.0
GiveWP <= 4.16.0 - Authenticated (Author+) Stored Cross-Site Scripting via 'block_id' Shortcode Attribute
- Medium 6.1
CVE-2025-13206unauthenticated≤ 4.13.0
GiveWP - Donation Plugin and Fundraising Platform <= 4.13.0 - Unauthenticated Stored Cross-Site Scripting via 'name'
- Medium 6.1
CVE-2024-35679unauthenticated · needs a click≤ 3.12.0
WordPress GiveWP plugin <= 3.12.0 - Reflected Cross Site Scripting (XSS) vulnerability
- Medium 6.1
CVE-2024-27987unauthenticated · needs a click≤ 3.3.1
WordPress Give plugin <= 3.3.1 - Reflected Cross Site Scripting (XSS) vulnerability
- Medium 5.4
CVE-2026-65464unauthenticated · needs a click≤ 4.16.3
WordPress GiveWP plugin <= 4.16.3 - Cross Site Request Forgery (CSRF) vulnerability
- Medium 5.4
CVE-2025-67467unauthenticated · needs a click≤ 4.13.1
WordPress GiveWP plugin <= 4.13.1 - Cross Site Request Forgery (CSRF) vulnerability
- Medium 5.4
CVE-2023-4247unauthenticated · needs a click≤ 2.33.3
GiveWP <= 2.33.3 - Cross-Site Request Forgery to plugin deactivation
- Medium 5.4
CVE-2025-7205login required≤ 4.5.0
GiveWP – Donation Plugin and Fundraising Platform <= 4.5.0 - Authenticated (GiveWP worker+) Stored Cross-Site Scripting
- Medium 5.4
CVE-2023-23672login required≤ 2.25.1
WordPress GiveWP plugin <= 2.25.1 - Arbitrary Content Deletion vulnerability
- Medium 5.4
CVE-2024-5941subscriber+≤ 3.14.1
GiveWP – Donation Plugin and Fundraising Platform <= 3.14.1 - Missing Authorization to Authenticated (Subscriber+) Limited File Deletion
- Medium 5.4
CVE-2024-5977login required≤ 3.13.0
GiveWP – Donation Plugin and Fundraising Platform <= 3.13.0 - Insecure Direct Object Reference to Authenticated (GiveWP Worker+) Arbitrary Post Actions
- Medium 5.4
CVE-2023-51415login required≤ 3.2.2
WordPress GiveWP Plugin <= 3.2.2 is vulnerable to Cross Site Scripting (XSS)
- Medium 5.4
CVE-2019-15317login required
The give plugin before 2.4.7 for WordPress has XSS via a donor name.
- Medium 5.4
CVE-2025-4571contributor+≤ 4.3.0
GiveWP – Donation Plugin and Fundraising Platform <= 4.3.0 - Missing Authorization To Authenticated (Contributor+) Campaign Data View And Modification
- Medium 5.4
CVE-2024-3714contributor+≤ 3.10.0
GiveWP – Donation Plugin and Fundraising Platform <= 3.10.0 - Authenticated (Contributor+) Stored Cross-Site Scripting
- Medium 5.4
CVE-2024-1957contributor+≤ 3.6.1
GiveWP – Donation Plugin and Fundraising Platform <= 3.6.1 -- Authenticated(Contributor+) Stored Cross-Site Scripting via Shortcode
- Medium 5.4
CVE-2024-1424contributor+≤ 3.5.1
GiveWP – Donation Plugin and Fundraising Platform <= 3.5.1 - Authenticated (Contributor+) Stored Cross-Site Scripting
- Medium 5.4
CVE-2023-23668contributor+≤ 2.25.1
WordPress GiveWP Plugin <= 2.25.1 is vulnerable to Cross Site Scripting (XSS)
- Medium 5.3
CVE-2026-97066unauthenticated≤ 4.16.9
WordPress GiveWP plugin <= 4.16.9 - Insecure Direct Object References (IDOR) vulnerability
- Medium 5.3
CVE-2026-73349unauthenticated→ 4.16.6
WordPress GiveWP plugin < 4.16.6 - Broken Access Control vulnerability
- Medium 5.3
CVE-2026-42642unauthenticated≤ 4.14.5
WordPress GiveWP plugin <= 4.14.5 - Broken Access Control vulnerability
- Medium 5.3
CVE-2025-66533unauthenticated≤ 4.13.1
WordPress GiveWP plugin <= 4.13.1 - Arbitrary Shortocde Execution vulnerability
- Medium 5.3
CVE-2025-11228unauthenticated≤ 4.10.0
GiveWP – Donation Plugin and Fundraising Platform <= 4.10.0 - Missing Authorization to Unauthenticated Forms-Campaign Association
- Medium 5.3
CVE-2025-8620unauthenticated≤ 4.6.0
GiveWP – Donation Plugin and Fundraising Platform <= 4.6.0 - Unauthenticated Donor Data Exposure
- Medium 5.3
CVE-2024-6551unauthenticated≤ 3.15.1
GiveWP <= 3.15.1 - Unauthenticated Full Path Disclosure
- Medium 5.3
CVE-2024-5940unauthenticated≤ 3.13.0
GiveWP – Donation Plugin and Fundraising Platform <= 3.13.0 - Missing Authorization to Unauthenticated Event Settings Update
- Medium 5.3
CVE-2024-5939unauthenticated≤ 3.13.0
GiveWP – Donation Plugin and Fundraising Platform <= 3.13.0 - Missing Authorization to Limited Information Exposure
- Medium 5.3
CVE-2022-2117unauthenticated≤ 2.20.2
GiveWP – Donation Plugin and Fundraising Platform <= 2.20.2 - Sensitive Information Disclosure
- Medium 4.9
CVE-2022-31475high privilege≤ 2.20.2
WordPress GiveWP plugin <= 2.20.2 - Authenticated Arbitrary File Read via Export function vulnerability
- Medium 4.8
CVE-2022-40211high privilege≤ 2.25.1
WordPress GiveWP plugin <= 2.25.1 - Cross Site Scripting (XSS) via render_dropdown vulnerability
- Medium 4.3
CVE-2026-11981unauthenticated · needs a click≤ 4.15.3
GiveWP <= 4.15.3 - Cross-Site Request Forgery
- Medium 4.3
CVE-2023-4248unauthenticated · needs a click≤ 2.33.3
GiveWP <= 2.33.3 - Cross-Site Request Forgery to Stripe Integration Deletion
- Medium 4.3
CVE-2023-4246unauthenticated · needs a click≤ 2.33.3
GiveWP <= 2.33.3 - Cross-Site Request Forgery to plugin installation
- Medium 4.3
CVE-2025-7221login required≤ 4.5.0
GiveWP – Donation Plugin and Fundraising Platform <= 4.5.0 - Missing Authorization to Donation Update
The access label is read from the record's own text (e.g. “subscriber+”: subscriber and above). When the text names no role, CVSS decides between “login required” and “high privilege”; no role name is invented. “Needs a click”: the attack depends on a logged-in user following a link (CSRF, reflected XSS).