← WordPress Vulnerabilities
WordPress security by component

Giveaways and Contests by RafflePress

Giveaways and Contests by RafflePress is a WordPress component with 10 published CVE records in this archive. The latest tracked vulnerability was published Nov 21, 2025; the highest CVE/CNA score is 7.2.

Plugin slug: rafflepress

CVE-2025-66064: Giveaways and Contests by RafflePress: Cross-site request forgery

Giveaways and Contests by RafflePress is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.

PublishedNov 21, 2025
Safe version guidanceSee mitigation notes
Safe version
Nov 21, 2025 CVE-2025-66064
Giveaways and Contests by RafflePress: Cross-site request forgery
Giveaways and Contests by RafflePress is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE4.3
NVDPending
Nov 19, 2025 CVE-2025-12484
Giveaways and Contests by RafflePress – Get More Website Traffic, Email Subscribers, and Social Followers: Cross-site scripting
Giveaways and Contests by RafflePress – Get More Website Traffic, Email Subscribers, and Social Followers is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE7.2
NVDPending
Jun 20, 2025 CVE-2025-49997
Giveaways and Contests by RafflePress: A security weakness
Giveaways and Contests by RafflePress is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.3
NVDPending
May 15, 2025 CVE-2024-10107
Giveaways and Contests by RafflePress: Cross-site scripting
Giveaways and Contests by RafflePress is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE4.8
NVDPending
Sep 12, 2024 CVE-2024-6887
Giveaways and Contests by RafflePress: Cross-site scripting
Giveaways and Contests by RafflePress is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE4.8
NVD4.8
Jul 13, 2024 CVE-2024-3963
Giveaways and Contests by RafflePress: Cross-site scripting
Giveaways and Contests by RafflePress is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.5
NVDPending
Jun 10, 2024 CVE-2024-4745
Giveaways and Contests by RafflePress: A security weakness
Giveaways and Contests by RafflePress is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE4.3
NVD6.3
May 17, 2024 CVE-2024-32827
Giveaways and Contests: Privilege escalation or authentication bypass
Giveaways and Contests is affected by privilege escalation or authentication bypass. Exposure depends on how the affected operation is made reachable by the site. A successful request can grant permissions or access that the caller should not possess.
See mitigation notes
CVE5.3
NVDPending
Mar 13, 2024 CVE-2024-1935
Giveaways and Contests by RafflePress – Get More Website Traffic, Email Subscribers, and Social Followers: Cross-site scripting
Giveaways and Contests by RafflePress – Get More Website Traffic, Email Subscribers, and Social Followers is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE7.2
NVD6.1
Oct 30, 2023 CVE-2023-5049
Giveaways and Contests by RafflePress: Cross-site scripting
Giveaways and Contests by RafflePress is affected by cross-site scripting. Exploitation requires an authenticated WordPress account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4