← WordPress Vulnerabilities
WordPress security by component

GiveWP – Donation Plugin and Fundraising Platform

GiveWP – Donation Plugin and Fundraising Platform provides tools for accepting donations, managing donors, creating fundraising forms, and tracking charitable contributions in WordPress.

GiveWP – Donation Plugin and Fundraising Platform (givewp) is a WordPress plugin with 29 published CVE records in this archive. The latest tracked vulnerability was published Jul 31, 2026; the highest published CVSS base score is 9.8.

Plugin slug: givewp

CVE-2026-14319: GiveWP REST access exposes anonymous recurring-donor records

GiveWP before 4.16.3 does not adequately restrict a REST API endpoint that returns recurring-donation records. An unauthenticated visitor can call the endpoint and retrieve information about anonymous recurring donors, including donor names and subscription details. The published.

PublishedJul 31, 2026
Known safe version4.16.3
Published vulnerabilities for givewp
Safe version
Jul 31, 2026 CVE-2026-14319
GiveWP REST access exposes anonymous recurring-donor records
GiveWP before 4.16.3 does not adequately restrict a REST API endpoint that returns recurring-donation records. An unauthenticated visitor can call the endpoint and retrieve information about anonymous recurring donors, including donor names and subscription details. The published.
4.16.3
CVE7.5
NVDPending
Jul 31, 2026 CVE-2026-14317
GiveWP accepts donations through administrator-disabled gateways
GiveWP before 4.16.3 derives the available payment-gateway set partly from unauthenticated request input instead of enforcing only the gateways enabled by the administrator. A visitor can select a disabled gateway and complete a donation through a payment path the site owner intentionally removed from service. The published.
4.16.3
CVE5.3
NVDPending
Jul 30, 2026 CVE-2026-14318
GiveWP Worker accounts can store script in public donation forms
GiveWP before 4.16.3 lets a user assigned the GiveWP Worker role edit a legacy donation form because the template-settings path accepts current_user_can('edit_post', form_id). Attacker-controlled legacy[display_settings][checkout_label] data is saved as the form's submit-button label and rendered without attribute escaping in the public form's submit input, including its data-before-validation-label attribute. An attribute-breakout payload can therefore execute in the site origin when any visitor loads the affected donation form. The issue requires a legacy option-based donation form and an administrator-assigned GiveWP Worker or more privileged role.
4.16.3
CVE6.8
NVDPending
Aug 06, 2025 CVE-2025-8620
GiveWP – Donation Plugin and Fundraising Platform: A security weakness
GiveWP – Donation Plugin and Fundraising Platform is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.3
NVD5.3
Mar 04, 2025 CVE-2025-0912
Donations Widget: Code execution
Donations Widget is affected by code execution. The vulnerable path is reachable without authentication. Successful exploitation can run attacker-controlled code in the WordPress hosting account.
See mitigation notes
CVE9.8
NVDPending
Jan 13, 2025 CVE-2025-22777
GiveWP: Code execution
GiveWP is affected by code execution. Exposure depends on how the affected operation is made reachable by the site. Successful exploitation can run attacker-controlled code in the WordPress hosting account.
See mitigation notes
CVE9.8
NVD9.8
Jan 11, 2025 CVE-2024-12877
GiveWP – Donation Plugin and Fundraising Platform: Code execution
GiveWP – Donation Plugin and Fundraising Platform is affected by code execution. The vulnerable path is reachable without authentication. Successful exploitation can run attacker-controlled code in the WordPress hosting account.
See mitigation notes
CVE9.8
NVDPending
Jan 02, 2025 CVE-2023-23672
GiveWP: A security weakness
GiveWP is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.4
NVD5.4
Jan 02, 2025 CVE-2023-47183
GiveWP: A security weakness
GiveWP is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.3
NVD9.8
Dec 27, 2024 CVE-2024-11921
GiveWP: Cross-site scripting
GiveWP is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE4.8
NVDPending
Sep 25, 2024 CVE-2024-47315
GiveWP: Cross-site request forgery
GiveWP is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE5.4
NVD8.8
May 18, 2024 CVE-2024-3714
GiveWP – Donation Plugin and Fundraising Platform: Cross-site scripting
GiveWP – Donation Plugin and Fundraising Platform is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
Apr 13, 2024 CVE-2024-1957
GiveWP – Donation Plugin and Fundraising Platform: Cross-site scripting
GiveWP – Donation Plugin and Fundraising Platform is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
Apr 09, 2024 CVE-2024-1424
GiveWP – Donation Plugin and Fundraising Platform: Cross-site scripting
GiveWP – Donation Plugin and Fundraising Platform is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
Jan 16, 2024 CVE-2023-0224
GiveWP: SQL injection
GiveWP is affected by SQL injection. The vulnerable path is reachable without authentication. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE9.8
NVD9.8
Feb 13, 2023 CVE-2022-4448
GiveWP: Cross-site scripting
GiveWP is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE5.4
NVD5.4
Aug 01, 2022 CVE-2022-2260
GiveWP: Denial of service
GiveWP is affected by denial of service. Exposure depends on how the affected operation is made reachable by the site. A successful request can exhaust or disrupt the affected operation and make site functionality unavailable.
See mitigation notes
CVEPending
NVD6.5
Aug 01, 2022 CVE-2022-2215
GiveWP: Cross-site scripting
GiveWP is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVEPending
NVD4.8
Jul 18, 2022 CVE-2022-2117
GiveWP: Sensitive information exposure
GiveWP is affected by sensitive information exposure. The vulnerable path is reachable without authentication. Successful exploitation can disclose data that should not be available to the caller.
See mitigation notes
CVE5.3
NVD5.3
Feb 21, 2022 CVE-2022-0252
GiveWP: Cross-site scripting
GiveWP is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVEPending
NVD6.1
Feb 21, 2022 CVE-2021-25100
GiveWP: Cross-site scripting
GiveWP is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVEPending
NVD6.1
Feb 21, 2022 CVE-2021-25099
GiveWP: Cross-site scripting
GiveWP is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVEPending
NVD6.1
Aug 23, 2021 CVE-2021-24524
GiveWP – Donation Plugin and Fundraising Platform: Cross-site scripting
GiveWP – Donation Plugin and Fundraising Platform is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVEPending
NVD4.8
May 17, 2021 CVE-2021-24315
GiveWP – Donation Plugin and Fundraising Platform: Cross-site scripting
GiveWP – Donation Plugin and Fundraising Platform is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVEPending
NVD4.8
Apr 12, 2021 CVE-2021-24213
GiveWP – Donation Plugin and Fundraising Platform: Cross-site scripting
GiveWP – Donation Plugin and Fundraising Platform is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVEPending
NVD6.1
Aug 31, 2020 CVE-2020-20627
Givewp: A security weakness
Givewp is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVEPending
NVD5.3
Jan 08, 2020 CVE-2019-20360
Givewp: A security weakness
Givewp is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE7.5
NVD7.5
Aug 15, 2019 CVE-2019-13578
Givewp: SQL injection
Givewp is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVEPending
NVD9.8
Mar 22, 2019 CVE-2019-9909
Givewp: Cross-site scripting
Givewp is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVEPending
NVD6.1