Vulnerabilities
Vulnerable Software
Givewp:  >> Givewp  >> 4.4.0  Security Vulnerabilities
The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 4.6.0. This makes it possible for unauthenticated attackers to extract donor names, emails, and donor id.
CVSS Score
5.3
EPSS Score
0.001
Published
2025-08-06
The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the donor notes parameter in all versions up to, and including, 4.5.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with GiveWP worker-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Additionally, they need to trick an administrator into visiting the legacy version of the site.
CVSS Score
5.4
EPSS Score
0.0
Published
2025-07-31


Contact Us

Shodan ® - All rights reserved