İçeriğe atla
Noroxi

GiveWP – Donation Plugin and Fundraising Platform

give · eklenti

GiveWP – Donation Plugin and Fundraising Platform için bilinen güvenlik açıkları. Sitenizde bu bileşenin hangi sürümünün çalıştığını WP Lens ile saniyede öğrenin.

68 bilinen açık

12 kritik · 5 kayıt için istismar kodu yayımlanmış · son kayıt 30 Eyl 2026

Güvenlik açıkları

  • CVE-2026-82222

    WordPress GiveWP plugin <= 4.16.7.1 - Remote Code Execution (RCE) vulnerability

    Kritik 10.0
  • CVE-2025-0912

    GiveWP – Donation Plugin and Fundraising Platform <= 3.19.4 - Unauthenticated PHP Object Injection

    Kritik 9.8
  • CVE-2025-22777

    WordPress GiveWP Plugin <= 3.19.3 - PHP Object Injection vulnerability

    Kritik 9.8
  • CVE-2024-12877

    GiveWP – Donation Plugin and Fundraising Platform <= 3.19.2 - Unauthenticated PHP Object Injection

    Kritik 9.8
  • CVE-2023-47183

    WordPress GiveWP plugin <= 2.33.1 - Broken Access Control vulnerability

    Kritik 9.8
  • CVE-2024-9634

    GiveWP – Donation Plugin and Fundraising Platform <= 3.16.3 - Unauthenticated PHP Object Injection to Remote Code Execution

    Kritik 9.8
  • CVE-2024-8353

    GiveWP – Donation Plugin and Fundraising Platform <= 3.16.1 - Unauthenticated PHP Object Injection

    Kritik 9.8
  • CVE-2024-5932

    GiveWP – Donation Plugin and Fundraising Platform <= 3.14.1 - Unauthenticated PHP Object Injection to Remote Code Execution

    Kritik 9.8
  • CVE-2024-37099

    WordPress GiveWP plugin <= 3.14.1 - Unauthenticated PHP Object Injection vulnerability

    Kritik 9.8
  • CVE-2023-32513

    WordPress GiveWP Plugin <= 2.25.3 is vulnerable to PHP Object Injection

    Kritik 9.8
  • CVE-2023-22719

    WordPress GiveWP Plugin <= 2.25.1 is vulnerable to CSV Injection

    Kritik 9.8
  • CVE-2026-97196

    WordPress GiveWP plugin <= 4.16.9 - Broken Authentication vulnerability

    Kritik 9.1
  • CVE-2024-47315

    WordPress GiveWP – Donation Plugin and Fundraising Platform plugin <= 3.15.1 - Cross Site Request Forgery (CSRF) vulnerability

    Yüksek 8.8
  • CVE-2023-41665

    WordPress GiveWP plugin <= 2.33.0 - GiveWP Manager+ Privilege Escalation vulnerability

    Yüksek 8.8
  • CVE-2023-25450

    WordPress GiveWP Plugin <= 2.25.1 is vulnerable to Cross Site Request Forgery (CSRF)

    Yüksek 8.8
  • CVE-2025-2025

    Give <= 3.22.0 - Missing Authorization to Unauthenticated Arbitrary Earning Reports Disclosure via give_reports_earnings Function

    Yüksek 7.5
  • CVE-2024-9130

    GiveWP – Donation Plugin and Fundraising Platform <= 3.16.1 - Authenticated (GiveWP Manager+) SQL Injection via order Parameter

    Yüksek 7.2
  • CVE-2024-30229

    WordPress Give plugin <= 3.4.2 - PHP Object Injection vulnerability

    Yüksek 7.2
  • CVE-2022-28700

    WordPress GiveWP plugin <= 2.20.2 - Authenticated Arbitrary File Creation via Export function vulnerability

    Yüksek 7.2
  • CVE-2026-96830

    WordPress GiveWP plugin <= 4.16.9 - Cross Site Scripting (XSS) vulnerability

    Yüksek 7.1
  • CVE-2026-66690

    WordPress GiveWP plugin <= 4.16.5 - Cross Site Scripting (XSS) vulnerability

    Yüksek 7.1
  • CVE-2026-65441

    WordPress GiveWP plugin <= 4.16.3 - Cross Site Scripting (XSS) vulnerability

    Yüksek 7.1
  • CVE-2026-34900

    WordPress GiveWP plugin <= 4.14.2 - Reflected Cross Site Scripting (XSS) vulnerability

    Yüksek 7.1
  • CVE-2026-42678

    WordPress GiveWP plugin <= 4.14.5 - Cross Site Scripting (XSS) vulnerability

    Yüksek 7.1
  • CVE-2026-96834

    WordPress GiveWP plugin <= 4.16.9 - Sensitive Data Exposure vulnerability

    Orta 6.5
  • CVE-2026-73352

    WordPress GiveWP plugin <= 4.16.5.1 - Broken Access Control vulnerability

    Orta 6.5
  • CVE-2026-73348→ 4.16.6

    WordPress GiveWP plugin < 4.16.6 - Broken Access Control vulnerability

    Orta 6.5
  • CVE-2026-73357→ 4.16.6

    WordPress GiveWP plugin < 4.16.6 - Cross Site Scripting (XSS) vulnerability

    Orta 6.5
  • CVE-2025-11227

    GiveWP – Donation Plugin and Fundraising Platform <= 4.10.0 - Missing Authorization to Unauthenticated Forms and Campaigns Disclosure

    Orta 6.5
  • CVE-2025-2331

    GiveWP – Donation Plugin and Fundraising Platform <= 3.22.1 - Authenticated (Subscriber+) Sensitive Information Exposure

    Orta 6.5
  • CVE-2022-40312

    WordPress GiveWP Plugin <= 2.25.1 is vulnerable to Server Side Request Forgery (SSRF)

    Orta 6.5
  • CVE-2026-5510

    GiveWP <= 4.14.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes

    Orta 6.4
  • CVE-2026-14987

    GiveWP <= 4.16.3 - Authenticated (Give Worker+) Stored Cross-Site Scripting via 'twitter_message' Sequoia Template Setting

    Orta 6.4
  • CVE-2026-13704

    GiveWP <= 4.16.1 - Authenticated (Give Worker+) Stored Cross-Site Scripting via Sequioa Form

    Orta 6.4
  • CVE-2026-13246

    GiveWP <= 4.16.0 - Authenticated (Author+) Stored Cross-Site Scripting via 'block_id' Shortcode Attribute

    Orta 6.4
  • CVE-2025-13206

    GiveWP - Donation Plugin and Fundraising Platform <= 4.13.0 - Unauthenticated Stored Cross-Site Scripting via 'name'

    Orta 6.1
  • CVE-2024-35679

    WordPress GiveWP plugin <= 3.12.0 - Reflected Cross Site Scripting (XSS) vulnerability

    Orta 6.1
  • CVE-2024-27987

    WordPress Give plugin <= 3.3.1 - Reflected Cross Site Scripting (XSS) vulnerability

    Orta 6.1
  • CVE-2026-65464

    WordPress GiveWP plugin <= 4.16.3 - Cross Site Request Forgery (CSRF) vulnerability

    Orta 5.4
  • CVE-2025-67467

    WordPress GiveWP plugin <= 4.13.1 - Cross Site Request Forgery (CSRF) vulnerability

    Orta 5.4
  • CVE-2025-7205

    GiveWP – Donation Plugin and Fundraising Platform <= 4.5.0 - Authenticated (GiveWP worker+) Stored Cross-Site Scripting

    Orta 5.4
  • CVE-2025-4571

    GiveWP – Donation Plugin and Fundraising Platform <= 4.3.0 - Missing Authorization To Authenticated (Contributor+) Campaign Data View And Modification

    Orta 5.4
  • CVE-2023-23672

    WordPress GiveWP plugin <= 2.25.1 - Arbitrary Content Deletion vulnerability

    Orta 5.4
  • CVE-2024-5941

    GiveWP – Donation Plugin and Fundraising Platform <= 3.14.1 - Missing Authorization to Authenticated (Subscriber+) Limited File Deletion

    Orta 5.4
  • CVE-2024-5977

    GiveWP – Donation Plugin and Fundraising Platform <= 3.13.0 - Insecure Direct Object Reference to Authenticated (GiveWP Worker+) Arbitrary Post Actions

    Orta 5.4
  • CVE-2024-3714

    GiveWP – Donation Plugin and Fundraising Platform <= 3.10.0 - Authenticated (Contributor+) Stored Cross-Site Scripting

    Orta 5.4
  • CVE-2024-1957

    GiveWP – Donation Plugin and Fundraising Platform <= 3.6.1 -- Authenticated(Contributor+) Stored Cross-Site Scripting via Shortcode

    Orta 5.4
  • CVE-2024-1424

    GiveWP – Donation Plugin and Fundraising Platform <= 3.5.1 - Authenticated (Contributor+) Stored Cross-Site Scripting

    Orta 5.4
  • CVE-2023-51415

    WordPress GiveWP Plugin <= 3.2.2 is vulnerable to Cross Site Scripting (XSS)

    Orta 5.4
  • CVE-2023-4247

    GiveWP <= 2.33.3 - Cross-Site Request Forgery to plugin deactivation

    Orta 5.4
  • CVE-2023-23668

    WordPress GiveWP Plugin <= 2.25.1 is vulnerable to Cross Site Scripting (XSS)

    Orta 5.4
  • CVE-2019-15317

    The give plugin before 2.4.7 for WordPress has XSS via a donor name.

    Orta 5.4
  • CVE-2026-97066

    WordPress GiveWP plugin <= 4.16.9 - Insecure Direct Object References (IDOR) vulnerability

    Orta 5.3
  • CVE-2026-73349→ 4.16.6

    WordPress GiveWP plugin < 4.16.6 - Broken Access Control vulnerability

    Orta 5.3
  • CVE-2026-42642

    WordPress GiveWP plugin <= 4.14.5 - Broken Access Control vulnerability

    Orta 5.3
  • CVE-2025-66533

    WordPress GiveWP plugin <= 4.13.1 - Arbitrary Shortocde Execution vulnerability

    Orta 5.3
  • CVE-2025-11228

    GiveWP – Donation Plugin and Fundraising Platform <= 4.10.0 - Missing Authorization to Unauthenticated Forms-Campaign Association

    Orta 5.3
  • CVE-2025-8620

    GiveWP – Donation Plugin and Fundraising Platform <= 4.6.0 - Unauthenticated Donor Data Exposure

    Orta 5.3
  • CVE-2024-6551

    GiveWP <= 3.15.1 - Unauthenticated Full Path Disclosure

    Orta 5.3
  • CVE-2024-5940

    GiveWP – Donation Plugin and Fundraising Platform <= 3.13.0 - Missing Authorization to Unauthenticated Event Settings Update

    Orta 5.3
  • CVE-2024-5939

    GiveWP – Donation Plugin and Fundraising Platform <= 3.13.0 - Missing Authorization to Limited Information Exposure

    Orta 5.3
  • CVE-2022-2117

    GiveWP – Donation Plugin and Fundraising Platform <= 2.20.2 - Sensitive Information Disclosure

    Orta 5.3
  • CVE-2022-31475

    WordPress GiveWP plugin <= 2.20.2 - Authenticated Arbitrary File Read via Export function vulnerability

    Orta 4.9
  • CVE-2022-40211

    WordPress GiveWP plugin <= 2.25.1 - Cross Site Scripting (XSS) via render_dropdown vulnerability

    Orta 4.8
  • CVE-2026-11981

    GiveWP <= 4.15.3 - Cross-Site Request Forgery

    Orta 4.3
  • CVE-2025-7221

    GiveWP – Donation Plugin and Fundraising Platform <= 4.5.0 - Missing Authorization to Donation Update

    Orta 4.3
  • CVE-2023-4248

    GiveWP <= 2.33.3 - Cross-Site Request Forgery to Stripe Integration Deletion

    Orta 4.3
  • CVE-2023-4246

    GiveWP <= 2.33.3 - Cross-Site Request Forgery to plugin installation

    Orta 4.3

← Dizine dön