WordPress security by component
GiveWP
Plugin description
GiveWP is a WordPress component with 45 published CVE records in this archive. The latest tracked vulnerability was published Jul 23, 2026; the highest CVE/CNA score is 10.
Plugin slug:
giveLatest vulnerability
CVE-2026-65464: GiveWP: Cross-site request forgery
GiveWP is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request. The published affected range is n/a through 4.16.3.
| Safe version |
|
||
|---|---|---|---|
| Jul 23, 2026 |
CVE-2026-65464
GiveWP: Cross-site request forgery
GiveWP is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request. The published affected range is n/a through 4.16.3.
|
4.16.4 |
CVE5.4
NVDPending
|
| Jul 16, 2026 |
CVE-2026-14987
GiveWP – Donation Plugin and Fundraising Platform: Cross-site scripting
GiveWP – Donation Plugin and Fundraising Platform is affected by cross-site scripting. Exploitation requires an authenticated WordPress account. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is <= 4.16.3.
|
> 4.16.3 |
CVE6.4
NVDPending
|
| Jul 02, 2026 |
CVE-2026-13704
GiveWP – Donation Plugin and Fundraising Platform: Cross-site scripting
GiveWP – Donation Plugin and Fundraising Platform is affected by cross-site scripting. Exploitation requires an authenticated WordPress account. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is <= 4.16.1.
|
> 4.16.1 |
CVE6.4
NVDPending
|
| Jul 01, 2026 |
CVE-2026-13246
GiveWP – Donation Plugin and Fundraising Platform: Cross-site scripting
GiveWP – Donation Plugin and Fundraising Platform is affected by cross-site scripting. Exploitation requires at least author-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is <= 4.16.0.
|
> 4.16.0 |
CVE6.4
NVDPending
|
| Jul 01, 2026 |
CVE-2026-11981
GiveWP – Donation Plugin and Fundraising Platform: Cross-site request forgery
GiveWP – Donation Plugin and Fundraising Platform is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request. The published affected range is <= 4.15.3.
|
> 4.15.3 |
CVE4.3
NVDPending
|
| Jun 15, 2026 |
CVE-2026-34900
GiveWP: Cross-site scripting
GiveWP is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is n/a through 4.14.2.
|
4.14.3 |
CVE7.1
NVDPending
|
| Jun 01, 2026 |
CVE-2026-42678
GiveWP: Cross-site scripting
GiveWP is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is n/a through 4.14.5.
|
4.14.6 |
CVE7.1
NVDPending
|
| Apr 29, 2026 |
CVE-2026-42642
GiveWP: A security weakness
GiveWP is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is <= 4.14.5.
|
4.14.6 |
CVE5.3
NVDPending
|
| Dec 09, 2025 |
CVE-2025-67467
GiveWP: Cross-site request forgery
GiveWP is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
|
See mitigation notes |
CVE5.4
NVDPending
|
| Dec 09, 2025 |
CVE-2025-66533
GiveWP: Code execution
GiveWP is affected by code execution. Exposure depends on how the affected operation is made reachable by the site. Successful exploitation can run attacker-controlled code in the WordPress hosting account.
|
See mitigation notes |
CVE5.3
NVDPending
|
| Nov 19, 2025 |
CVE-2025-13206
GiveWP – Donation Plugin and Fundraising Platform: Cross-site scripting
GiveWP – Donation Plugin and Fundraising Platform is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE7.2
NVD6.1
|
| Oct 04, 2025 |
CVE-2025-11228
GiveWP – Donation Plugin and Fundraising Platform: A security weakness
GiveWP – Donation Plugin and Fundraising Platform is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE5.3
NVDPending
|
| Oct 04, 2025 |
CVE-2025-11227
GiveWP – Donation Plugin and Fundraising Platform: A security weakness
GiveWP – Donation Plugin and Fundraising Platform is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE6.5
NVD6.5
|
| Aug 21, 2025 |
CVE-2025-7221
GiveWP – Donation Plugin and Fundraising Platform: A security weakness
GiveWP – Donation Plugin and Fundraising Platform is affected by a security weakness. Exploitation requires an authenticated WordPress account. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE4.3
NVDPending
|
| Jul 31, 2025 |
CVE-2025-7205
GiveWP – Donation Plugin and Fundraising Platform: Cross-site scripting
GiveWP – Donation Plugin and Fundraising Platform is affected by cross-site scripting. Exploitation requires an authenticated WordPress account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE5.4
NVDPending
|
| Jun 19, 2025 |
CVE-2025-4571
GiveWP – Donation Plugin and Fundraising Platform: A security weakness
GiveWP – Donation Plugin and Fundraising Platform is affected by a security weakness. Exploitation requires at least contributor-level access. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE5.4
NVDPending
|
| Mar 22, 2025 |
CVE-2025-2331
GiveWP – Donation Plugin and Fundraising Platform: Sensitive information exposure
GiveWP – Donation Plugin and Fundraising Platform is affected by sensitive information exposure. Exploitation requires at least subscriber-level access. Successful exploitation can disclose data that should not be available to the caller.
|
See mitigation notes |
CVE5.3
NVD6.5
|
| Mar 15, 2025 |
CVE-2025-2025
GiveWP – Donation Plugin and Fundraising Platform: A security weakness
GiveWP – Donation Plugin and Fundraising Platform is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE6.5
NVD7.5
|
| Oct 16, 2024 |
CVE-2024-9634
GiveWP – Donation Plugin and Fundraising Platform: Code execution
GiveWP – Donation Plugin and Fundraising Platform is affected by code execution. The vulnerable path is reachable without authentication. Successful exploitation can run attacker-controlled code in the WordPress hosting account.
|
See mitigation notes |
CVE9.8
NVDPending
|
| Sep 28, 2024 |
CVE-2024-8353
GiveWP – Donation Plugin and Fundraising Platform: Code execution
GiveWP – Donation Plugin and Fundraising Platform is affected by code execution. The vulnerable path is reachable without authentication. Successful exploitation can run attacker-controlled code in the WordPress hosting account.
|
See mitigation notes |
CVE9.8
NVD9.8
|
| Sep 27, 2024 |
CVE-2024-9130
GiveWP – Donation Plugin and Fundraising Platform: SQL injection
GiveWP – Donation Plugin and Fundraising Platform is affected by SQL injection. Exploitation requires an authenticated WordPress account. A successful request can alter database queries and expose or modify WordPress data.
|
See mitigation notes |
CVE7.2
NVDPending
|
| Aug 29, 2024 |
CVE-2024-6551
GiveWP – Donation Plugin and Fundraising Platform: A security weakness
GiveWP – Donation Plugin and Fundraising Platform is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE5.3
NVD5.3
|
| Aug 20, 2024 |
CVE-2024-5941
GiveWP – Donation Plugin and Fundraising Platform: A security weakness
GiveWP – Donation Plugin and Fundraising Platform is affected by a security weakness. Exploitation requires at least subscriber-level access. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE5.4
NVDPending
|
| Aug 20, 2024 |
CVE-2024-5940
GiveWP – Donation Plugin and Fundraising Platform: A security weakness
GiveWP – Donation Plugin and Fundraising Platform is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE6.5
NVD5.3
|
| Aug 20, 2024 |
CVE-2024-5939
GiveWP – Donation Plugin and Fundraising Platform: A security weakness
GiveWP – Donation Plugin and Fundraising Platform is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE5.3
NVDPending
|
| Aug 20, 2024 |
CVE-2024-5932
GiveWP – Donation Plugin and Fundraising Platform: Code execution
GiveWP – Donation Plugin and Fundraising Platform is affected by code execution. The vulnerable path is reachable without authentication. Successful exploitation can run attacker-controlled code in the WordPress hosting account.
|
See mitigation notes |
CVE10.0
NVD9.8
|
| Aug 19, 2024 |
CVE-2024-37099
GiveWP: Code execution
GiveWP is affected by code execution. Exposure depends on how the affected operation is made reachable by the site. Successful exploitation can run attacker-controlled code in the WordPress hosting account.
|
See mitigation notes |
CVE10.0
NVD9.8
|
| Jul 19, 2024 |
CVE-2024-5977
GiveWP – Donation Plugin and Fundraising Platform: A security weakness
GiveWP – Donation Plugin and Fundraising Platform is affected by a security weakness. Exploitation requires an authenticated WordPress account. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE5.4
NVD5.4
|
| Jun 08, 2024 |
CVE-2024-35679
GiveWP: Cross-site scripting
GiveWP is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE7.1
NVD6.1
|
| May 17, 2024 |
CVE-2023-41665
GiveWP: Privilege escalation or authentication bypass
GiveWP is affected by privilege escalation or authentication bypass. Exposure depends on how the affected operation is made reachable by the site. A successful request can grant permissions or access that the caller should not possess.
|
See mitigation notes |
CVE8.8
NVD8.8
|
| Apr 12, 2024 |
CVE-2022-40211
GiveWP: Cross-site scripting
GiveWP is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE5.9
NVD4.8
|
| Mar 28, 2024 |
CVE-2024-30229
GiveWP: Code execution
GiveWP is affected by code execution. Exposure depends on how the affected operation is made reachable by the site. Successful exploitation can run attacker-controlled code in the WordPress hosting account.
|
See mitigation notes |
CVE8.0
NVD7.2
|
| Mar 15, 2024 |
CVE-2024-27987
GiveWP: Cross-site scripting
GiveWP is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE7.1
NVD6.1
|
| Feb 10, 2024 |
CVE-2023-51415
GiveWP – Donation Plugin and Fundraising Platform: Cross-site scripting
GiveWP – Donation Plugin and Fundraising Platform is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.5
NVD5.4
|
| Jan 11, 2024 |
CVE-2023-4248
GiveWP: Cross-site request forgery
GiveWP is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
|
See mitigation notes |
CVE5.4
NVD4.3
|
| Jan 11, 2024 |
CVE-2023-4247
GiveWP: Cross-site request forgery
GiveWP is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
|
See mitigation notes |
CVE5.4
NVD5.4
|
| Jan 11, 2024 |
CVE-2023-4246
GiveWP: Cross-site request forgery
GiveWP is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
|
See mitigation notes |
CVE4.3
NVD4.3
|
| Dec 28, 2023 |
CVE-2023-32513
GiveWP – Donation Plugin and Fundraising Platform: Code execution
GiveWP – Donation Plugin and Fundraising Platform is affected by code execution. Exposure depends on how the affected operation is made reachable by the site. Successful exploitation can run attacker-controlled code in the WordPress hosting account.
|
See mitigation notes |
CVE7.5
NVD9.8
|
| Dec 18, 2023 |
CVE-2022-40312
GiveWP – Donation Plugin and Fundraising Platform: Server-side request forgery
GiveWP – Donation Plugin and Fundraising Platform is affected by server-side request forgery. Exposure depends on how the affected operation is made reachable by the site. The vulnerable server can be induced to make attacker-selected network requests.
|
See mitigation notes |
CVE5.5
NVD6.5
|
| Nov 07, 2023 |
CVE-2023-22719
GiveWP: A security weakness
GiveWP is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE4.7
NVD9.8
|
| Jun 15, 2023 |
CVE-2023-25450
Give: Cross-site request forgery
Give is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
|
See mitigation notes |
CVE5.4
NVD8.8
|
| May 08, 2023 |
CVE-2023-23668
Give: Cross-site scripting
Give is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.5
NVD5.4
|
| Jul 21, 2022 |
CVE-2022-31475
GiveWP: Filesystem traversal
GiveWP is affected by filesystem traversal. Exposure depends on how the affected operation is made reachable by the site. A crafted path can escape the intended directory and reach files or directories elsewhere on the server.
|
See mitigation notes |
CVE5.5
NVD4.9
|
| Jul 21, 2022 |
CVE-2022-28700
GiveWP: A security weakness
GiveWP is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE9.1
NVD7.2
|
| Aug 22, 2019 |
CVE-2019-15317
Give: Cross-site scripting
Give is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE5.4
NVD5.4
|