GiveWP – Donation Plugin and Fundraising Platform <= 4.14.2 - Reflected Cross-Site Scripting
GiveWP – Donation Plugin and Fundraising Platform
Minimum safe version
4.14.6
Update to 4.14.6 or later to address 89 fixable vulnerabilities
CVE-2026-42642
GiveWP <= 4.13.1 - Unauthenticated Arbitrary Shortcode Execution
GiveWP <= 4.13.1 - Cross-Site Request Forgery
CVE-2025-13206
CVE-2025-11228
CVE-2025-11227
GiveWP – Donation Plugin and Fundraising Platform <= 4.5.0 - Missing Authorization to Donation Update
FiboSearch <= 1.32.1 - Missing Authorization
GiveWP – Donation Plugin and Fundraising Platform <= 4.6.0 - Unauthenticated Donor Data Exposure
GiveWP – Donation Plugin and Fundraising Platform <= 4.5.0 - Authenticated (GiveWP worker+) Stored Cross-Site Scripting
GiveWP – Donation Plugin and Fundraising Platform <= 4.3.0 - Missing Authorization To Authenticated (Contributor+) Campaign Data View And Modification
GiveWP – Donation Plugin and Fundraising Platform <= 3.22.1 - Authenticated (Subscriber+) Sensitive Information Exposure
Give <= 3.22.0 - Missing Authorization to Unauthenticated Arbitrary Earning Reports Disclosure via give_reports_earnings Function
GiveWP – Donation Plugin and Fundraising Platform <= 3.19.4 - Unauthenticated PHP Object Injection
CVE-2025-22777
CVE-2024-12877
CVE-2024-11921
CVE-2024-9634
WordPress GiveWP Plugin <= 3.16.1 is vulnerable to PHP Object Injection
CVE-2024-9130
CVE-2024-47315
CVE-2024-6551
CVE-2024-5940
CVE-2024-5939
CVE-2024-5932
CVE-2024-5941
CVE-2024-37099
CVE-2024-5977
CVE-2024-35679
WordPress GiveWP Plugin <= 3.10.0 is vulnerable to Cross Site Scripting (XSS)
WordPress GiveWP Plugin <= 3.6.1 is vulnerable to Cross Site Scripting (XSS)
GiveWP – Donation Plugin and Fundraising Platform <= 3.4.2 - Authenticated (GiveWP Manager+) PHP Object Injection
CVE-2024-1424
CVE-2024-27987
CVE-2023-51415
CVE-2023-47183
CVE-2023-4248
CVE-2023-4247
CVE-2023-4246
CVE-2023-41665
Give - Donation Plugin <= 2.33.0 - Authenticated(Give Manager+) Privilege Escalation
GiveWP < 2.25.3 - Cross-Site Request Forgery
Give - Cross-Site Scripting (XSS)
Give < 2.21.0 - Reflected Cross-Site Scripting
CVE-2023-32513
WordPress GiveWP Plugin <= 2.25.2 is vulnerable to Cross Site Request Forgery (CSRF)
GiveWP <= 2.25.2 - Cross-Site Request Forgery via give_ajax_store_payment_note
GiveWP <= 2.25.2 - Cross-Site Request Forgery via give_ajax_delete_payment_note
GiveWP <= 2.25.2 - Cross-Site Request Forgery
CVE-2023-23668
CVE-2023-25450
CVE-2022-40211
CVE-2023-22719
CVE-2023-23672
CVE-2022-40312
GiveWP <= 2.25.1 - Cross-Site Request Forgery via give_cache_flush
GiveWP <= 2.25.1 - Unauthenticated CSV Injection
GiveWP <= 2.25.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via give_form_grid shortcode
GiveWP <= 2.25.1 - Authenticated (Admin+) Server-Side Request Forgery via give_get_content_by_ajax_handler
GiveWP <= 2.25.1 - Cross-Site Request Forgery via save
GiveWP <= 2.25.1 - Cross-Site Request Forgery to Cross-Site Scripting via render_dropdown
GiveWP <= 2.25.1 - Cross-Site Request Forgery via process_bulk_action
CVE-2023-0224
GiveWP <= 2.23.2 - Unauthenticated SQL Injection
CVE-2022-4448
GiveWP – Donation Plugin and Fundraising Platform < 0.8.5 - Reflected Cross-Site Scripting
CVE-2022-2215
CVE-2022-28700
CVE-2022-2260
CVE-2022-31475
WordPress GiveWP plugin <= 2.20.2 - Reflected Cross-Site Scripting (XSS) vulnerability
CVE-2022-2117
WordPress Give Plugin <= 0.8.4 - Cross Site Scripting (XSS)
WordPress Give plugin <= 2.5.0 - SQL Injection (SQLi) vulnerability
WordPress GiveWp plugin <= 2.5.4 - Authentication Bypass
WordPress GiveWP plugin <= 2.9.7 - Reflected Cross-Site Scripting (XSS) vulnerability
WordPress GiveWP plugin <= 2.10.1 - Authenticated Persistent Cross-Site Scripting (XSS) vulnerability
CVE-2019-9909
CVE-2019-13578
CVE-2019-15317
CVE-2019-20360
CVE-2020-20627
CVE-2021-24213
CVE-2021-24315
CVE-2021-24524
CVE-2021-25100
CVE-2021-25099
CVE-2022-0252