Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

GiveWP — Vulnerabilities & Security Advisories 12

Browse all 12 CVE security advisories affecting GiveWP. AI-powered Chinese analysis, POCs, and references for each vulnerability.

GiveWP is a WordPress donation plugin enabling organizations to collect payments through various gateways. Historically, it has been susceptible to multiple remote code execution vulnerabilities, cross-site scripting (XSS), privilege escalations, and authentication bypasses. The plugin's 12 recorded CVEs highlight recurring issues in input validation, access control, and insecure deserialization. Notable incidents include multiple critical flaws allowing attackers to execute arbitrary code or compromise administrative accounts, often through insufficient sanitization of user inputs. Despite these vulnerabilities, GiveWP remains widely adopted, necessitating regular updates and careful configuration to mitigate security risks.

Found 6 results / 12 Clear Filters
CVE ID Title CVSS Severity Published
CVE-2023-51415 WordPress GiveWP Plugin <= 3.2.2 is vulnerable to Cross Site Scripting (XSS) — GiveWP – Donation Plugin and Fundraising Platform CWE-79 6.5 Medium 2024-02-10
CVE-2023-32513 WordPress GiveWP Plugin <= 2.25.3 is vulnerable to PHP Object Injection — GiveWP – Donation Plugin and Fundraising Platform CWE-502 7.5 High 2023-12-28
CVE-2022-40312 WordPress GiveWP Plugin <= 2.25.1 is vulnerable to Server Side Request Forgery (SSRF) — GiveWP – Donation Plugin and Fundraising Platform CWE-918 5.5 Medium 2023-12-18
CVE-2023-25450 WordPress GiveWP Plugin <= 2.25.1 is vulnerable to Cross Site Request Forgery (CSRF) — GiveWP – Donation Plugin and Fundraising Platform CWE-352 5.4 Medium 2023-06-15
CVE-2021-24315 Give WP < 2.10.4 - Authenticated Stored Cross-Site Scripting (XSS) — GiveWP – Donation Plugin and Fundraising Platform CWE-79 4.8 - 2021-05-17
CVE-2021-24213 GiveWP < 2.10.0 - Reflected Cross Site Scripting (XSS) — GiveWP – Donation Plugin and Fundraising Platform CWE-79 6.1 - 2021-04-12

This page lists every published CVE security advisory associated with GiveWP. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.