GiveWP – Donation Plugin and Fundraising Platform
give · eklenti
GiveWP – Donation Plugin and Fundraising Platform için bilinen güvenlik açıkları. Sitenizde bu bileşenin hangi sürümünün çalıştığını WP Lens ile saniyede öğrenin.
68 bilinen açık
12 kritik · 5 kayıt için istismar kodu yayımlanmış · son kayıt 30 Eyl 2026
Güvenlik açıkları
- Kritik 10.0
WordPress GiveWP plugin <= 4.16.7.1 - Remote Code Execution (RCE) vulnerability
- Kritik 9.8
GiveWP – Donation Plugin and Fundraising Platform <= 3.19.4 - Unauthenticated PHP Object Injection
- Kritik 9.8
WordPress GiveWP Plugin <= 3.19.3 - PHP Object Injection vulnerability
- Kritik 9.8
GiveWP – Donation Plugin and Fundraising Platform <= 3.19.2 - Unauthenticated PHP Object Injection
- Kritik 9.8
WordPress GiveWP plugin <= 2.33.1 - Broken Access Control vulnerability
- Kritik 9.8
GiveWP – Donation Plugin and Fundraising Platform <= 3.16.3 - Unauthenticated PHP Object Injection to Remote Code Execution
- Kritik 9.8
GiveWP – Donation Plugin and Fundraising Platform <= 3.16.1 - Unauthenticated PHP Object Injection
- Kritik 9.8
GiveWP – Donation Plugin and Fundraising Platform <= 3.14.1 - Unauthenticated PHP Object Injection to Remote Code Execution
- Kritik 9.8
WordPress GiveWP plugin <= 3.14.1 - Unauthenticated PHP Object Injection vulnerability
- Kritik 9.8
WordPress GiveWP Plugin <= 2.25.3 is vulnerable to PHP Object Injection
- Kritik 9.8
WordPress GiveWP Plugin <= 2.25.1 is vulnerable to CSV Injection
- Kritik 9.1
WordPress GiveWP plugin <= 4.16.9 - Broken Authentication vulnerability
- Yüksek 8.8
WordPress GiveWP – Donation Plugin and Fundraising Platform plugin <= 3.15.1 - Cross Site Request Forgery (CSRF) vulnerability
- Yüksek 8.8
WordPress GiveWP plugin <= 2.33.0 - GiveWP Manager+ Privilege Escalation vulnerability
- Yüksek 8.8
WordPress GiveWP Plugin <= 2.25.1 is vulnerable to Cross Site Request Forgery (CSRF)
- Yüksek 7.5
Give <= 3.22.0 - Missing Authorization to Unauthenticated Arbitrary Earning Reports Disclosure via give_reports_earnings Function
- Yüksek 7.2
GiveWP – Donation Plugin and Fundraising Platform <= 3.16.1 - Authenticated (GiveWP Manager+) SQL Injection via order Parameter
- Yüksek 7.2
WordPress Give plugin <= 3.4.2 - PHP Object Injection vulnerability
- Yüksek 7.2
WordPress GiveWP plugin <= 2.20.2 - Authenticated Arbitrary File Creation via Export function vulnerability
- Yüksek 7.1
WordPress GiveWP plugin <= 4.16.9 - Cross Site Scripting (XSS) vulnerability
- Yüksek 7.1
WordPress GiveWP plugin <= 4.16.5 - Cross Site Scripting (XSS) vulnerability
- Yüksek 7.1
WordPress GiveWP plugin <= 4.16.3 - Cross Site Scripting (XSS) vulnerability
- Yüksek 7.1
WordPress GiveWP plugin <= 4.14.2 - Reflected Cross Site Scripting (XSS) vulnerability
- Yüksek 7.1
WordPress GiveWP plugin <= 4.14.5 - Cross Site Scripting (XSS) vulnerability
- Orta 6.5
WordPress GiveWP plugin <= 4.16.9 - Sensitive Data Exposure vulnerability
- Orta 6.5
WordPress GiveWP plugin <= 4.16.5.1 - Broken Access Control vulnerability
- Orta 6.5
CVE-2026-73348→ 4.16.6
WordPress GiveWP plugin < 4.16.6 - Broken Access Control vulnerability
- Orta 6.5
CVE-2026-73357→ 4.16.6
WordPress GiveWP plugin < 4.16.6 - Cross Site Scripting (XSS) vulnerability
- Orta 6.5
GiveWP – Donation Plugin and Fundraising Platform <= 4.10.0 - Missing Authorization to Unauthenticated Forms and Campaigns Disclosure
- Orta 6.5
GiveWP – Donation Plugin and Fundraising Platform <= 3.22.1 - Authenticated (Subscriber+) Sensitive Information Exposure
- Orta 6.5
WordPress GiveWP Plugin <= 2.25.1 is vulnerable to Server Side Request Forgery (SSRF)
- Orta 6.4
GiveWP <= 4.14.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes
- Orta 6.4
GiveWP <= 4.16.3 - Authenticated (Give Worker+) Stored Cross-Site Scripting via 'twitter_message' Sequoia Template Setting
- Orta 6.4
GiveWP <= 4.16.1 - Authenticated (Give Worker+) Stored Cross-Site Scripting via Sequioa Form
- Orta 6.4
GiveWP <= 4.16.0 - Authenticated (Author+) Stored Cross-Site Scripting via 'block_id' Shortcode Attribute
- Orta 6.1
GiveWP - Donation Plugin and Fundraising Platform <= 4.13.0 - Unauthenticated Stored Cross-Site Scripting via 'name'
- Orta 6.1
WordPress GiveWP plugin <= 3.12.0 - Reflected Cross Site Scripting (XSS) vulnerability
- Orta 6.1
WordPress Give plugin <= 3.3.1 - Reflected Cross Site Scripting (XSS) vulnerability
- Orta 5.4
WordPress GiveWP plugin <= 4.16.3 - Cross Site Request Forgery (CSRF) vulnerability
- Orta 5.4
WordPress GiveWP plugin <= 4.13.1 - Cross Site Request Forgery (CSRF) vulnerability
- Orta 5.4
GiveWP – Donation Plugin and Fundraising Platform <= 4.5.0 - Authenticated (GiveWP worker+) Stored Cross-Site Scripting
- Orta 5.4
GiveWP – Donation Plugin and Fundraising Platform <= 4.3.0 - Missing Authorization To Authenticated (Contributor+) Campaign Data View And Modification
- Orta 5.4
WordPress GiveWP plugin <= 2.25.1 - Arbitrary Content Deletion vulnerability
- Orta 5.4
GiveWP – Donation Plugin and Fundraising Platform <= 3.14.1 - Missing Authorization to Authenticated (Subscriber+) Limited File Deletion
- Orta 5.4
GiveWP – Donation Plugin and Fundraising Platform <= 3.13.0 - Insecure Direct Object Reference to Authenticated (GiveWP Worker+) Arbitrary Post Actions
- Orta 5.4
GiveWP – Donation Plugin and Fundraising Platform <= 3.10.0 - Authenticated (Contributor+) Stored Cross-Site Scripting
- Orta 5.4
GiveWP – Donation Plugin and Fundraising Platform <= 3.6.1 -- Authenticated(Contributor+) Stored Cross-Site Scripting via Shortcode
- Orta 5.4
GiveWP – Donation Plugin and Fundraising Platform <= 3.5.1 - Authenticated (Contributor+) Stored Cross-Site Scripting
- Orta 5.4
WordPress GiveWP Plugin <= 3.2.2 is vulnerable to Cross Site Scripting (XSS)
- Orta 5.4
GiveWP <= 2.33.3 - Cross-Site Request Forgery to plugin deactivation
- Orta 5.4
WordPress GiveWP Plugin <= 2.25.1 is vulnerable to Cross Site Scripting (XSS)
- Orta 5.4
The give plugin before 2.4.7 for WordPress has XSS via a donor name.
- Orta 5.3
WordPress GiveWP plugin <= 4.16.9 - Insecure Direct Object References (IDOR) vulnerability
- Orta 5.3
CVE-2026-73349→ 4.16.6
WordPress GiveWP plugin < 4.16.6 - Broken Access Control vulnerability
- Orta 5.3
WordPress GiveWP plugin <= 4.14.5 - Broken Access Control vulnerability
- Orta 5.3
WordPress GiveWP plugin <= 4.13.1 - Arbitrary Shortocde Execution vulnerability
- Orta 5.3
GiveWP – Donation Plugin and Fundraising Platform <= 4.10.0 - Missing Authorization to Unauthenticated Forms-Campaign Association
- Orta 5.3
GiveWP – Donation Plugin and Fundraising Platform <= 4.6.0 - Unauthenticated Donor Data Exposure
- Orta 5.3
GiveWP <= 3.15.1 - Unauthenticated Full Path Disclosure
- Orta 5.3
GiveWP – Donation Plugin and Fundraising Platform <= 3.13.0 - Missing Authorization to Unauthenticated Event Settings Update
- Orta 5.3
GiveWP – Donation Plugin and Fundraising Platform <= 3.13.0 - Missing Authorization to Limited Information Exposure
- Orta 5.3
GiveWP – Donation Plugin and Fundraising Platform <= 2.20.2 - Sensitive Information Disclosure
- Orta 4.9
WordPress GiveWP plugin <= 2.20.2 - Authenticated Arbitrary File Read via Export function vulnerability
- Orta 4.8
WordPress GiveWP plugin <= 2.25.1 - Cross Site Scripting (XSS) via render_dropdown vulnerability
- Orta 4.3
GiveWP <= 4.15.3 - Cross-Site Request Forgery
- Orta 4.3
GiveWP – Donation Plugin and Fundraising Platform <= 4.5.0 - Missing Authorization to Donation Update
- Orta 4.3
GiveWP <= 2.33.3 - Cross-Site Request Forgery to Stripe Integration Deletion
- Orta 4.3
GiveWP <= 2.33.3 - Cross-Site Request Forgery to plugin installation