Skip to content
Noroxi

GiveWP – Donation Plugin and Fundraising Platform

give · plugin

Known security vulnerabilities for GiveWP – Donation Plugin and Fundraising Platform. Find out in seconds which version runs on your site with WP Lens.

68 known vulnerabilities

12 critical · 42 exploitable without logging in · 5 with public exploit code · latest Sep 30, 2026

Listed on wordpress.org · latest 4.18.0 · last updated Oct 1, 2026 · 100K+ installs

wordpress.org status checked on Oct 2, 2026

Vulnerabilities

  • CVE-2026-82222unauthenticated≤ 4.16.7.1

    WordPress GiveWP plugin <= 4.16.7.1 - Remote Code Execution (RCE) vulnerability

    Critical 10.0
  • CVE-2025-0912unauthenticated≤ 3.19.4

    GiveWP – Donation Plugin and Fundraising Platform <= 3.19.4 - Unauthenticated PHP Object Injection

    Critical 9.8
  • CVE-2025-22777unauthenticated≤ 3.19.3

    WordPress GiveWP Plugin <= 3.19.3 - PHP Object Injection vulnerability

    Critical 9.8
  • CVE-2024-12877unauthenticated≤ 3.19.2

    GiveWP – Donation Plugin and Fundraising Platform <= 3.19.2 - Unauthenticated PHP Object Injection

    Critical 9.8
  • CVE-2023-47183unauthenticated≤ 2.33.1

    WordPress GiveWP plugin <= 2.33.1 - Broken Access Control vulnerability

    Critical 9.8
  • CVE-2024-9634unauthenticated≤ 3.16.3

    GiveWP – Donation Plugin and Fundraising Platform <= 3.16.3 - Unauthenticated PHP Object Injection to Remote Code Execution

    Critical 9.8
  • CVE-2024-8353unauthenticated≤ 3.16.1

    GiveWP – Donation Plugin and Fundraising Platform <= 3.16.1 - Unauthenticated PHP Object Injection

    Critical 9.8
  • CVE-2024-5932unauthenticated≤ 3.14.1

    GiveWP – Donation Plugin and Fundraising Platform <= 3.14.1 - Unauthenticated PHP Object Injection to Remote Code Execution

    Critical 9.8
  • CVE-2024-37099unauthenticated≤ 3.14.1

    WordPress GiveWP plugin <= 3.14.1 - Unauthenticated PHP Object Injection vulnerability

    Critical 9.8
  • CVE-2023-32513unauthenticated · needs a click≤ 2.25.3

    WordPress GiveWP Plugin <= 2.25.3 is vulnerable to PHP Object Injection

    Critical 9.8
  • CVE-2023-22719unauthenticated · needs a click≤ 2.25.1

    WordPress GiveWP Plugin <= 2.25.1 is vulnerable to CSV Injection

    Critical 9.8
  • CVE-2026-97196unauthenticated≤ 4.16.9

    WordPress GiveWP plugin <= 4.16.9 - Broken Authentication vulnerability

    Critical 9.1
  • CVE-2024-47315unauthenticated · needs a click≤ 3.15.1

    WordPress GiveWP – Donation Plugin and Fundraising Platform plugin <= 3.15.1 - Cross Site Request Forgery (CSRF) vulnerability

    High 8.8
  • CVE-2023-25450unauthenticated · needs a click≤ 2.25.1

    WordPress GiveWP Plugin <= 2.25.1 is vulnerable to Cross Site Request Forgery (CSRF)

    High 8.8
  • CVE-2023-41665login required≤ 2.33.0

    WordPress GiveWP plugin <= 2.33.0 - GiveWP Manager+ Privilege Escalation vulnerability

    High 8.8
  • CVE-2025-2025unauthenticated≤ 3.22.0

    Give <= 3.22.0 - Missing Authorization to Unauthenticated Arbitrary Earning Reports Disclosure via give_reports_earnings Function

    High 7.5
  • CVE-2024-9130high privilege≤ 3.16.1

    GiveWP – Donation Plugin and Fundraising Platform <= 3.16.1 - Authenticated (GiveWP Manager+) SQL Injection via order Parameter

    High 7.2
  • CVE-2024-30229high privilege≤ 3.4.2

    WordPress Give plugin <= 3.4.2 - PHP Object Injection vulnerability

    High 7.2
  • CVE-2022-28700high privilege≤ 2.20.2

    WordPress GiveWP plugin <= 2.20.2 - Authenticated Arbitrary File Creation via Export function vulnerability

    High 7.2
  • CVE-2026-96830unauthenticated · needs a click≤ 4.16.9

    WordPress GiveWP plugin <= 4.16.9 - Cross Site Scripting (XSS) vulnerability

    High 7.1
  • CVE-2026-66690unauthenticated · needs a click≤ 4.16.5

    WordPress GiveWP plugin <= 4.16.5 - Cross Site Scripting (XSS) vulnerability

    High 7.1
  • CVE-2026-65441unauthenticated · needs a click≤ 4.16.3

    WordPress GiveWP plugin <= 4.16.3 - Cross Site Scripting (XSS) vulnerability

    High 7.1
  • CVE-2026-34900unauthenticated · needs a click≤ 4.14.2

    WordPress GiveWP plugin <= 4.14.2 - Reflected Cross Site Scripting (XSS) vulnerability

    High 7.1
  • CVE-2026-42678unauthenticated · needs a click≤ 4.14.5

    WordPress GiveWP plugin <= 4.14.5 - Cross Site Scripting (XSS) vulnerability

    High 7.1
  • CVE-2026-73352unauthenticated≤ 4.16.5.1

    WordPress GiveWP plugin <= 4.16.5.1 - Broken Access Control vulnerability

    Medium 6.5
  • CVE-2026-73348unauthenticated→ 4.16.6

    WordPress GiveWP plugin < 4.16.6 - Broken Access Control vulnerability

    Medium 6.5
  • CVE-2025-11227unauthenticated≤ 4.10.0

    GiveWP – Donation Plugin and Fundraising Platform <= 4.10.0 - Missing Authorization to Unauthenticated Forms and Campaigns Disclosure

    Medium 6.5
  • CVE-2026-96834subscriber+≤ 4.16.9

    WordPress GiveWP plugin <= 4.16.9 - Sensitive Data Exposure vulnerability

    Medium 6.5
  • CVE-2026-73357login required→ 4.16.6

    WordPress GiveWP plugin < 4.16.6 - Cross Site Scripting (XSS) vulnerability

    Medium 6.5
  • CVE-2025-2331subscriber+≤ 3.22.1

    GiveWP – Donation Plugin and Fundraising Platform <= 3.22.1 - Authenticated (Subscriber+) Sensitive Information Exposure

    Medium 6.5
  • CVE-2022-40312high privilege≤ 2.25.1

    WordPress GiveWP Plugin <= 2.25.1 is vulnerable to Server Side Request Forgery (SSRF)

    Medium 6.5
  • CVE-2026-14987login required≤ 4.16.3

    GiveWP <= 4.16.3 - Authenticated (Give Worker+) Stored Cross-Site Scripting via 'twitter_message' Sequoia Template Setting

    Medium 6.4
  • CVE-2026-13704login required≤ 4.16.1

    GiveWP <= 4.16.1 - Authenticated (Give Worker+) Stored Cross-Site Scripting via Sequioa Form

    Medium 6.4
  • CVE-2026-5510contributor+≤ 4.14.4

    GiveWP <= 4.14.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes

    Medium 6.4
  • CVE-2026-13246author+≤ 4.16.0

    GiveWP <= 4.16.0 - Authenticated (Author+) Stored Cross-Site Scripting via 'block_id' Shortcode Attribute

    Medium 6.4
  • CVE-2025-13206unauthenticated≤ 4.13.0

    GiveWP - Donation Plugin and Fundraising Platform <= 4.13.0 - Unauthenticated Stored Cross-Site Scripting via 'name'

    Medium 6.1
  • CVE-2024-35679unauthenticated · needs a click≤ 3.12.0

    WordPress GiveWP plugin <= 3.12.0 - Reflected Cross Site Scripting (XSS) vulnerability

    Medium 6.1
  • CVE-2024-27987unauthenticated · needs a click≤ 3.3.1

    WordPress Give plugin <= 3.3.1 - Reflected Cross Site Scripting (XSS) vulnerability

    Medium 6.1
  • CVE-2026-65464unauthenticated · needs a click≤ 4.16.3

    WordPress GiveWP plugin <= 4.16.3 - Cross Site Request Forgery (CSRF) vulnerability

    Medium 5.4
  • CVE-2025-67467unauthenticated · needs a click≤ 4.13.1

    WordPress GiveWP plugin <= 4.13.1 - Cross Site Request Forgery (CSRF) vulnerability

    Medium 5.4
  • CVE-2023-4247unauthenticated · needs a click≤ 2.33.3

    GiveWP <= 2.33.3 - Cross-Site Request Forgery to plugin deactivation

    Medium 5.4
  • CVE-2025-7205login required≤ 4.5.0

    GiveWP – Donation Plugin and Fundraising Platform <= 4.5.0 - Authenticated (GiveWP worker+) Stored Cross-Site Scripting

    Medium 5.4
  • CVE-2023-23672login required≤ 2.25.1

    WordPress GiveWP plugin <= 2.25.1 - Arbitrary Content Deletion vulnerability

    Medium 5.4
  • CVE-2024-5941subscriber+≤ 3.14.1

    GiveWP – Donation Plugin and Fundraising Platform <= 3.14.1 - Missing Authorization to Authenticated (Subscriber+) Limited File Deletion

    Medium 5.4
  • CVE-2024-5977login required≤ 3.13.0

    GiveWP – Donation Plugin and Fundraising Platform <= 3.13.0 - Insecure Direct Object Reference to Authenticated (GiveWP Worker+) Arbitrary Post Actions

    Medium 5.4
  • CVE-2023-51415login required≤ 3.2.2

    WordPress GiveWP Plugin <= 3.2.2 is vulnerable to Cross Site Scripting (XSS)

    Medium 5.4
  • CVE-2019-15317login required

    The give plugin before 2.4.7 for WordPress has XSS via a donor name.

    Medium 5.4
  • CVE-2025-4571contributor+≤ 4.3.0

    GiveWP – Donation Plugin and Fundraising Platform <= 4.3.0 - Missing Authorization To Authenticated (Contributor+) Campaign Data View And Modification

    Medium 5.4
  • CVE-2024-3714contributor+≤ 3.10.0

    GiveWP – Donation Plugin and Fundraising Platform <= 3.10.0 - Authenticated (Contributor+) Stored Cross-Site Scripting

    Medium 5.4
  • CVE-2024-1957contributor+≤ 3.6.1

    GiveWP – Donation Plugin and Fundraising Platform <= 3.6.1 -- Authenticated(Contributor+) Stored Cross-Site Scripting via Shortcode

    Medium 5.4
  • CVE-2024-1424contributor+≤ 3.5.1

    GiveWP – Donation Plugin and Fundraising Platform <= 3.5.1 - Authenticated (Contributor+) Stored Cross-Site Scripting

    Medium 5.4
  • CVE-2023-23668contributor+≤ 2.25.1

    WordPress GiveWP Plugin <= 2.25.1 is vulnerable to Cross Site Scripting (XSS)

    Medium 5.4
  • CVE-2026-97066unauthenticated≤ 4.16.9

    WordPress GiveWP plugin <= 4.16.9 - Insecure Direct Object References (IDOR) vulnerability

    Medium 5.3
  • CVE-2026-73349unauthenticated→ 4.16.6

    WordPress GiveWP plugin < 4.16.6 - Broken Access Control vulnerability

    Medium 5.3
  • CVE-2026-42642unauthenticated≤ 4.14.5

    WordPress GiveWP plugin <= 4.14.5 - Broken Access Control vulnerability

    Medium 5.3
  • CVE-2025-66533unauthenticated≤ 4.13.1

    WordPress GiveWP plugin <= 4.13.1 - Arbitrary Shortocde Execution vulnerability

    Medium 5.3
  • CVE-2025-11228unauthenticated≤ 4.10.0

    GiveWP – Donation Plugin and Fundraising Platform <= 4.10.0 - Missing Authorization to Unauthenticated Forms-Campaign Association

    Medium 5.3
  • CVE-2025-8620unauthenticated≤ 4.6.0

    GiveWP – Donation Plugin and Fundraising Platform <= 4.6.0 - Unauthenticated Donor Data Exposure

    Medium 5.3
  • CVE-2024-6551unauthenticated≤ 3.15.1

    GiveWP <= 3.15.1 - Unauthenticated Full Path Disclosure

    Medium 5.3
  • CVE-2024-5940unauthenticated≤ 3.13.0

    GiveWP – Donation Plugin and Fundraising Platform <= 3.13.0 - Missing Authorization to Unauthenticated Event Settings Update

    Medium 5.3
  • CVE-2024-5939unauthenticated≤ 3.13.0

    GiveWP – Donation Plugin and Fundraising Platform <= 3.13.0 - Missing Authorization to Limited Information Exposure

    Medium 5.3
  • CVE-2022-2117unauthenticated≤ 2.20.2

    GiveWP – Donation Plugin and Fundraising Platform <= 2.20.2 - Sensitive Information Disclosure

    Medium 5.3
  • CVE-2022-31475high privilege≤ 2.20.2

    WordPress GiveWP plugin <= 2.20.2 - Authenticated Arbitrary File Read via Export function vulnerability

    Medium 4.9
  • CVE-2022-40211high privilege≤ 2.25.1

    WordPress GiveWP plugin <= 2.25.1 - Cross Site Scripting (XSS) via render_dropdown vulnerability

    Medium 4.8
  • CVE-2026-11981unauthenticated · needs a click≤ 4.15.3

    GiveWP <= 4.15.3 - Cross-Site Request Forgery

    Medium 4.3
  • CVE-2023-4248unauthenticated · needs a click≤ 2.33.3

    GiveWP <= 2.33.3 - Cross-Site Request Forgery to Stripe Integration Deletion

    Medium 4.3
  • CVE-2023-4246unauthenticated · needs a click≤ 2.33.3

    GiveWP <= 2.33.3 - Cross-Site Request Forgery to plugin installation

    Medium 4.3
  • CVE-2025-7221login required≤ 4.5.0

    GiveWP – Donation Plugin and Fundraising Platform <= 4.5.0 - Missing Authorization to Donation Update

    Medium 4.3

The access label is read from the record's own text (e.g. “subscriber+”: subscriber and above). When the text names no role, CVSS decides between “login required” and “high privilege”; no role name is invented. “Needs a click”: the attack depends on a logged-in user following a link (CSRF, reflected XSS).

← Back to directory