WordPress security changelog
MEDIUM CVE-2025-4571 Analyzed

GiveWP – Donation Plugin and Fundraising Platform: A security weakness

GiveWP – Donation Plugin and Fundraising Platform is affected by a security weakness. Exploitation requires at least contributor-level access. The resulting impact depends on how the affected component exposes the vulnerable operation.

CVE / CNA score 5.4 CVSS 3.1 · security@wordfence.com
NVD score Pending NVD has not published its own CVSS assessment.
Component
GiveWP – Donation Plugin and Fundraising Platform
Plugin slug
give
Affected
See vendor advisory
Safe version
See mitigation notes
Published
Jun 19, 2025
Weakness
CWE-862 — Missing Authorization

This CVE was published Jun 19, 2025 and is one of 45 known issues for this plugin.

Patch or disable the affected component.

Update GiveWP – Donation Plugin and Fundraising Platform to a release outside the affected range, or disable and remove it until a fixed version is available.

Technical description

The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to unauthorized view and modification of data due to an insufficient capability check on the permissionsCheck functions in all versions up to, and including, 4.3.0. This makes it possible for authenticated attackers, with Contributor-level access and above, to view or delete fundraising campaigns, view donors' data, modify campaign events, etc.

CVE / CNA vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N

Primary and upstream sources