CVE Tools

Givewp

19 CVEs tracked since 2022. Since Feb 2022, none of them reached CISA KEV.

Givewp CVEs per month

Feb 2022 to Sep 2024. Point at a month, or focus the strip and use the arrow keys.
Givewp CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2022-0230
2022-03null or fewer
2022-04null or fewer
2022-05null or fewer
2022-06null or fewer
2022-0730
2022-08null or fewer
2022-09null or fewer
2022-10null or fewer
2022-11null or fewer
2022-12null or fewer
2023-01null or fewer
2023-02null or fewer
2023-03null or fewer
2023-04null or fewer
2023-05null or fewer
2023-06null or fewer
2023-07null or fewer
2023-08null or fewer
2023-09null or fewer
2023-10null or fewer
2023-11null or fewer
2023-12null or fewer
2024-0140
2024-02null or fewer
2024-03null or fewer
2024-04null or fewer
2024-05null or fewer
2024-06null or fewer
2024-07null or fewer
2024-0860
2024-0930

Products

The products that kept showing up in Givewp's monthly top three, with their CVEs summed over those months.

  1. Givewp195 months
  2. Givewp (WordPress Plugin)21 month

Latest CVEs

The 15 most recently published vulnerabilities affecting Givewp.

  1. CVE-2025-13206GiveWP - Donation Plugin and Fundraising Platform <= 4.13.0 - Unauthenticated Stored Cross-Site Scripting via 'name'7.2
  2. CVE-2025-11228GiveWP – Donation Plugin and Fundraising Platform <= 4.10.0 - Missing Authorization to Unauthenticated Forms-Campaign Association5.3
  3. CVE-2025-11227GiveWP – Donation Plugin and Fundraising Platform <= 4.10.0 - Missing Authorization to Unauthenticated Forms and Campaigns Disclosure6.5
  4. CVE-2025-7221GiveWP – Donation Plugin and Fundraising Platform <= 4.5.0 - Missing Authorization to Donation Update4.3
  5. CVE-2025-8620GiveWP – Donation Plugin and Fundraising Platform <= 4.6.0 - Unauthenticated Donor Data Exposure5.3
  6. CVE-2025-7205GiveWP – Donation Plugin and Fundraising Platform <= 4.5.0 - Authenticated (GiveWP worker+) Stored Cross-Site Scripting5.4
  7. CVE-2025-4571GiveWP – Donation Plugin and Fundraising Platform <= 4.3.0 - Missing Authorization To Authenticated (Contributor+) Campaign Data View And Modification5.4
  8. CVE-2025-2331GiveWP – Donation Plugin and Fundraising Platform <= 3.22.1 - Authenticated (Subscriber+) Sensitive Information Exposure5.3
  9. CVE-2025-2025Give <= 3.22.0 - Missing Authorization to Unauthenticated Arbitrary Earning Reports Disclosure via give_reports_earnings Function6.5
  10. CVE-2025-0912GiveWP – Donation Plugin and Fundraising Platform <= 3.19.4 - Unauthenticated PHP Object Injection9.8
  11. CVE-2025-22777WordPress GiveWP Plugin <= 3.19.3 - PHP Object Injection vulnerability9.8
  12. CVE-2024-12877GiveWP – Donation Plugin and Fundraising Platform <= 3.19.2 - Unauthenticated PHP Object Injection9.8
  13. CVE-2023-23672WordPress GiveWP plugin <= 2.25.1 - Arbitrary Content Deletion vulnerability5.4
  14. CVE-2023-47183WordPress GiveWP plugin <= 2.33.1 - Broken Access Control vulnerability5.3
  15. CVE-2024-11921Give < 3.19.0 - Reflected XSS4.8

The record

Peak rank
#106 in Aug 2024
Busiest month shown
Aug 2024, 6 CVEs
Months with a KEV entry
0 since Feb 2022
Monthly snapshots
5 since 2022
Givewp's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store