WordPress Simple Giveaways plugin <= 2.49.0 - Cross Site Request Forgery (CSRF) vulnerability
Simple Giveaways – Grow your business, email lists and traffic with contests
Minimum safe version
2.48.2
Update to 2.48.2 or later to address 14 fixable vulnerabilities
CVE-2025-30819
Freemius SDK <= 2.4.2 - Missing Authorization Checks
WordPress Simple Giveaways Plugin <= 2.46.0 is vulnerable to Cross Site Scripting (XSS)
CVE-2023-23893
CVE-2023-31086
WordPress Simple Giveaways Plugin < 2.45.1 is vulnerable to Cross Site Scripting (XSS)
CVE-2023-1121
WordPress Simple Giveaways Plugin < 2.45.1 is vulnerable to Cross Site Scripting (XSS)
Freemius SDK <= 2.2.3 - Missing Authorization to Arbitrary Options Update
Freemius SDK <= 2.4.2 - Missing Authorization Checks
Freemius Library < 2.2.4 - Subscriber+ Arbitrary Option Update
WordPress Simple Giveaways plugin <= 2.42.0 - Sensitive Information Disclosure vulnerability
WordPress Simple Giveaways plugin <= 2.42.0 - Toggle The Debug Mode via Cross-Site Request Forgery (CSRF) vulnerability
CVE-2021-24298