Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1310 CNY

100%

GiveWP — Vulnerabilities & Security Advisories 19

All 19 CVE vulnerabilities found in GiveWP, with AI-generated Chinese analysis, references, and POCs.

GiveWP is a WordPress donation plugin developed by GiveWP that has been identified as having multiple security weaknesses. This page aggregates reports of vulnerabilities affecting GiveWP, covering incidents reported from 2018 through 2023. These entries include various issue types such as cross-site scripting, authorization bypasses, and insecure direct object references that have impacted the stability and security of the software. Readers can utilize this resource to track vendor advisories issued by the GiveWP team, understand the characteristics and risks associated with specific weakness classes, and look up a product's vulnerability history to assess long-term maintenance quality. The data is organized to help security professionals, developers, and site administrators evaluate the risk profile of the donation plugin. By examining past disclosures, users can identify patterns in software quality and make informed decisions about whether to update or replace the current implementation. This aggregation serves as a centralized reference for understanding the security landscape surrounding GiveWP without requiring searches across disparate sources. All listed vulnerabilities are sourced from public advisories and recognized security databases. The information provided is intended solely for educational and risk assessment purposes. It does not constitute an endorsement or criticism of the vendor. Users are encouraged to cross-reference this data with official changelogs and patch notes for the most accurate guidance on remediation strategies and version compatibility.

Vendor: Unknown

CVE IDTitleCVSSSeverityPublished
CVE-2026-42678 WordPress GiveWP plugin <= 4.14.5 - Cross Site Scripting (XSS) vulnerability CWE-79 7.1 High2026-06-01
CVE-2026-42642 WordPress GiveWP plugin <= 4.14.5 - Broken Access Control vulnerability CWE-862 5.3 Medium2026-04-29
CVE-2025-67467 WordPress GiveWP plugin <= 4.13.1 - Cross Site Request Forgery (CSRF) vulnerability CWE-352 5.4 Medium2025-12-09
CVE-2025-66533 WordPress GiveWP plugin <= 4.13.1 - Arbitrary Shortocde Execution vulnerability CWE-94 6.5 Medium2025-12-09
CVE-2025-22777 WordPress GiveWP Plugin <= 3.19.3 - PHP Object Injection vulnerability CWE-502 9.8 Critical2025-01-13
CVE-2023-23672 WordPress GiveWP plugin <= 2.25.1 - Arbitrary Content Deletion vulnerability CWE-862 5.4 Medium2025-01-02
CVE-2023-47183 WordPress GiveWP plugin <= 2.33.1 - Broken Access Control vulnerability CWE-862 5.3 Medium2025-01-02
CVE-2024-11921 Give < 3.19.0 - Reflected XSS 6.1 -2024-12-27
CVE-2024-47315 WordPress GiveWP – Donation Plugin and Fundraising Platform plugin <= 3.15.1 - Cross Site Request Forgery (CSRF) vulnerability CWE-352 5.4 Medium2024-09-25
CVE-2024-37099 WordPress GiveWP plugin <= 3.14.1 - Unauthenticated PHP Object Injection vulnerability CWE-502 10.0 Critical2024-08-19
CVE-2024-35679 WordPress GiveWP plugin <= 3.12.0 - Reflected Cross Site Scripting (XSS) vulnerability CWE-79 7.1 High2024-06-08
CVE-2023-41665 WordPress GiveWP plugin <= 2.33.0 - GiveWP Manager+ Privilege Escalation vulnerability CWE-269 8.8 High2024-05-17
CVE-2022-40211 WordPress GiveWP plugin <= 2.25.1 - Cross Site Scripting (XSS) via render_dropdown vulnerability CWE-79 5.9 Medium2024-04-12
CVE-2024-30229 WordPress Give plugin <= 3.4.2 - PHP Object Injection vulnerability CWE-502 8.0 High2024-03-28
CVE-2024-27987 WordPress Give plugin <= 3.3.1 - Reflected Cross Site Scripting (XSS) vulnerability CWE-79 7.1 High2024-03-15
CVE-2023-0224 GiveWP < 2.24.1 - Unauthenticated SQLi 9.8AICriticalAI2024-01-16
CVE-2023-22719 WordPress GiveWP Plugin <= 2.25.1 is vulnerable to CSV Injection CWE-1236 4.7 Medium2023-11-07
CVE-2023-23668 WordPress GiveWP Plugin <= 2.25.1 is vulnerable to Cross Site Scripting (XSS) CWE-79 6.5 Medium2023-05-08
CVE-2022-4448 GiveWP < 2.24.0 - Contributor+ Stored XSS 5.4 -2023-02-13

All 19 known CVE vulnerabilities affecting GiveWP with full Chinese analysis, references, and POCs where available.