← WordPress Vulnerabilities
WordPress security by component

GiveWP

GiveWP is a WordPress component with 45 published CVE records in this archive. The latest tracked vulnerability was published Jul 23, 2026; the highest CVE/CNA score is 10.

Plugin slug: give

CVE-2026-65464: GiveWP: Cross-site request forgery

GiveWP is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request. The published affected range is n/a through 4.16.3.

PublishedJul 23, 2026
Known safe version4.16.4
Safe version
Jul 23, 2026 CVE-2026-65464
GiveWP: Cross-site request forgery
GiveWP is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request. The published affected range is n/a through 4.16.3.
4.16.4
CVE5.4
NVDPending
Jul 16, 2026 CVE-2026-14987
GiveWP – Donation Plugin and Fundraising Platform: Cross-site scripting
GiveWP – Donation Plugin and Fundraising Platform is affected by cross-site scripting. Exploitation requires an authenticated WordPress account. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is <= 4.16.3.
> 4.16.3
CVE6.4
NVDPending
Jul 02, 2026 CVE-2026-13704
GiveWP – Donation Plugin and Fundraising Platform: Cross-site scripting
GiveWP – Donation Plugin and Fundraising Platform is affected by cross-site scripting. Exploitation requires an authenticated WordPress account. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is <= 4.16.1.
> 4.16.1
CVE6.4
NVDPending
Jul 01, 2026 CVE-2026-13246
GiveWP – Donation Plugin and Fundraising Platform: Cross-site scripting
GiveWP – Donation Plugin and Fundraising Platform is affected by cross-site scripting. Exploitation requires at least author-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is <= 4.16.0.
> 4.16.0
CVE6.4
NVDPending
Jul 01, 2026 CVE-2026-11981
GiveWP – Donation Plugin and Fundraising Platform: Cross-site request forgery
GiveWP – Donation Plugin and Fundraising Platform is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request. The published affected range is <= 4.15.3.
> 4.15.3
CVE4.3
NVDPending
Jun 15, 2026 CVE-2026-34900
GiveWP: Cross-site scripting
GiveWP is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is n/a through 4.14.2.
4.14.3
CVE7.1
NVDPending
Jun 01, 2026 CVE-2026-42678
GiveWP: Cross-site scripting
GiveWP is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is n/a through 4.14.5.
4.14.6
CVE7.1
NVDPending
Apr 29, 2026 CVE-2026-42642
GiveWP: A security weakness
GiveWP is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is <= 4.14.5.
4.14.6
CVE5.3
NVDPending
Dec 09, 2025 CVE-2025-67467
GiveWP: Cross-site request forgery
GiveWP is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE5.4
NVDPending
Dec 09, 2025 CVE-2025-66533
GiveWP: Code execution
GiveWP is affected by code execution. Exposure depends on how the affected operation is made reachable by the site. Successful exploitation can run attacker-controlled code in the WordPress hosting account.
See mitigation notes
CVE5.3
NVDPending
Nov 19, 2025 CVE-2025-13206
GiveWP – Donation Plugin and Fundraising Platform: Cross-site scripting
GiveWP – Donation Plugin and Fundraising Platform is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE7.2
NVD6.1
Oct 04, 2025 CVE-2025-11228
GiveWP – Donation Plugin and Fundraising Platform: A security weakness
GiveWP – Donation Plugin and Fundraising Platform is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.3
NVDPending
Oct 04, 2025 CVE-2025-11227
GiveWP – Donation Plugin and Fundraising Platform: A security weakness
GiveWP – Donation Plugin and Fundraising Platform is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE6.5
NVD6.5
Aug 21, 2025 CVE-2025-7221
GiveWP – Donation Plugin and Fundraising Platform: A security weakness
GiveWP – Donation Plugin and Fundraising Platform is affected by a security weakness. Exploitation requires an authenticated WordPress account. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE4.3
NVDPending
Jul 31, 2025 CVE-2025-7205
GiveWP – Donation Plugin and Fundraising Platform: Cross-site scripting
GiveWP – Donation Plugin and Fundraising Platform is affected by cross-site scripting. Exploitation requires an authenticated WordPress account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE5.4
NVDPending
Jun 19, 2025 CVE-2025-4571
GiveWP – Donation Plugin and Fundraising Platform: A security weakness
GiveWP – Donation Plugin and Fundraising Platform is affected by a security weakness. Exploitation requires at least contributor-level access. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.4
NVDPending
Mar 22, 2025 CVE-2025-2331
GiveWP – Donation Plugin and Fundraising Platform: Sensitive information exposure
GiveWP – Donation Plugin and Fundraising Platform is affected by sensitive information exposure. Exploitation requires at least subscriber-level access. Successful exploitation can disclose data that should not be available to the caller.
See mitigation notes
CVE5.3
NVD6.5
Mar 15, 2025 CVE-2025-2025
GiveWP – Donation Plugin and Fundraising Platform: A security weakness
GiveWP – Donation Plugin and Fundraising Platform is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE6.5
NVD7.5
Oct 16, 2024 CVE-2024-9634
GiveWP – Donation Plugin and Fundraising Platform: Code execution
GiveWP – Donation Plugin and Fundraising Platform is affected by code execution. The vulnerable path is reachable without authentication. Successful exploitation can run attacker-controlled code in the WordPress hosting account.
See mitigation notes
CVE9.8
NVDPending
Sep 28, 2024 CVE-2024-8353
GiveWP – Donation Plugin and Fundraising Platform: Code execution
GiveWP – Donation Plugin and Fundraising Platform is affected by code execution. The vulnerable path is reachable without authentication. Successful exploitation can run attacker-controlled code in the WordPress hosting account.
See mitigation notes
CVE9.8
NVD9.8
Sep 27, 2024 CVE-2024-9130
GiveWP – Donation Plugin and Fundraising Platform: SQL injection
GiveWP – Donation Plugin and Fundraising Platform is affected by SQL injection. Exploitation requires an authenticated WordPress account. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE7.2
NVDPending
Aug 29, 2024 CVE-2024-6551
GiveWP – Donation Plugin and Fundraising Platform: A security weakness
GiveWP – Donation Plugin and Fundraising Platform is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.3
NVD5.3
Aug 20, 2024 CVE-2024-5941
GiveWP – Donation Plugin and Fundraising Platform: A security weakness
GiveWP – Donation Plugin and Fundraising Platform is affected by a security weakness. Exploitation requires at least subscriber-level access. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.4
NVDPending
Aug 20, 2024 CVE-2024-5940
GiveWP – Donation Plugin and Fundraising Platform: A security weakness
GiveWP – Donation Plugin and Fundraising Platform is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE6.5
NVD5.3
Aug 20, 2024 CVE-2024-5939
GiveWP – Donation Plugin and Fundraising Platform: A security weakness
GiveWP – Donation Plugin and Fundraising Platform is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.3
NVDPending
Aug 20, 2024 CVE-2024-5932
GiveWP – Donation Plugin and Fundraising Platform: Code execution
GiveWP – Donation Plugin and Fundraising Platform is affected by code execution. The vulnerable path is reachable without authentication. Successful exploitation can run attacker-controlled code in the WordPress hosting account.
See mitigation notes
CVE10.0
NVD9.8
Aug 19, 2024 CVE-2024-37099
GiveWP: Code execution
GiveWP is affected by code execution. Exposure depends on how the affected operation is made reachable by the site. Successful exploitation can run attacker-controlled code in the WordPress hosting account.
See mitigation notes
CVE10.0
NVD9.8
Jul 19, 2024 CVE-2024-5977
GiveWP – Donation Plugin and Fundraising Platform: A security weakness
GiveWP – Donation Plugin and Fundraising Platform is affected by a security weakness. Exploitation requires an authenticated WordPress account. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.4
NVD5.4
Jun 08, 2024 CVE-2024-35679
GiveWP: Cross-site scripting
GiveWP is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE7.1
NVD6.1
May 17, 2024 CVE-2023-41665
GiveWP: Privilege escalation or authentication bypass
GiveWP is affected by privilege escalation or authentication bypass. Exposure depends on how the affected operation is made reachable by the site. A successful request can grant permissions or access that the caller should not possess.
See mitigation notes
CVE8.8
NVD8.8
Apr 12, 2024 CVE-2022-40211
GiveWP: Cross-site scripting
GiveWP is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE5.9
NVD4.8
Mar 28, 2024 CVE-2024-30229
GiveWP: Code execution
GiveWP is affected by code execution. Exposure depends on how the affected operation is made reachable by the site. Successful exploitation can run attacker-controlled code in the WordPress hosting account.
See mitigation notes
CVE8.0
NVD7.2
Mar 15, 2024 CVE-2024-27987
GiveWP: Cross-site scripting
GiveWP is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE7.1
NVD6.1
Feb 10, 2024 CVE-2023-51415
GiveWP – Donation Plugin and Fundraising Platform: Cross-site scripting
GiveWP – Donation Plugin and Fundraising Platform is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.5
NVD5.4
Jan 11, 2024 CVE-2023-4248
GiveWP: Cross-site request forgery
GiveWP is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE5.4
NVD4.3
Jan 11, 2024 CVE-2023-4247
GiveWP: Cross-site request forgery
GiveWP is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE5.4
NVD5.4
Jan 11, 2024 CVE-2023-4246
GiveWP: Cross-site request forgery
GiveWP is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE4.3
NVD4.3
Dec 28, 2023 CVE-2023-32513
GiveWP – Donation Plugin and Fundraising Platform: Code execution
GiveWP – Donation Plugin and Fundraising Platform is affected by code execution. Exposure depends on how the affected operation is made reachable by the site. Successful exploitation can run attacker-controlled code in the WordPress hosting account.
See mitigation notes
CVE7.5
NVD9.8
Dec 18, 2023 CVE-2022-40312
GiveWP – Donation Plugin and Fundraising Platform: Server-side request forgery
GiveWP – Donation Plugin and Fundraising Platform is affected by server-side request forgery. Exposure depends on how the affected operation is made reachable by the site. The vulnerable server can be induced to make attacker-selected network requests.
See mitigation notes
CVE5.5
NVD6.5
Nov 07, 2023 CVE-2023-22719
GiveWP: A security weakness
GiveWP is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE4.7
NVD9.8
Jun 15, 2023 CVE-2023-25450
Give: Cross-site request forgery
Give is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE5.4
NVD8.8
May 08, 2023 CVE-2023-23668
Give: Cross-site scripting
Give is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.5
NVD5.4
Jul 21, 2022 CVE-2022-31475
GiveWP: Filesystem traversal
GiveWP is affected by filesystem traversal. Exposure depends on how the affected operation is made reachable by the site. A crafted path can escape the intended directory and reach files or directories elsewhere on the server.
See mitigation notes
CVE5.5
NVD4.9
Jul 21, 2022 CVE-2022-28700
GiveWP: A security weakness
GiveWP is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE9.1
NVD7.2
Aug 22, 2019 CVE-2019-15317
Give: Cross-site scripting
Give is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE5.4
NVD5.4