Givewp

WordPress plugin · givewp · WordPress.org ↗
0
Critical
2
High
5
Known total
0
Unfixed
Running Givewp on your site? WP Alerts checks your installed version against every entry below and emails you only when one affects you. Free, no tracking.
Scan a site Monitor my sites →
SeverityVulnerabilityAffectedFixed inCVEPublished
HIGH
CVSS 8.1
GiveWP < 4.16.8.1 - Unauthenticated Account Takeover via Donor Email Sanitization Mismatch
CVE.org
>=4.16.6, <4.16.8.1 v4.16.8.1 CVE-2026-85530 Sep 16, 2026
HIGH
CVSS 7.5
GiveWP < 4.16.3 - Unauthenticated Recurring Donor Information Disclosure
CVE.org
>=0, <4.16.3 v4.16.3 CVE-2026-14319 Jul 31, 2026
MEDIUM
CVSS 6.5
GiveWP < 4.16.9 - Unauthenticated Arbitrary Shortcode Execution via Donor Name
CVE.org
>=4.13.2, <4.16.9 v4.16.9 CVE-2026-85113 Sep 21, 2026
MEDIUM
CVSS 5.3
GiveWP < 4.16.3 - Unauthenticated Payment Gateway Restriction Bypass
CVE.org
>=0, <4.16.3 v4.16.3 CVE-2026-14317 Jul 31, 2026
MEDIUM
CVSS 6.8
GiveWP < 4.16.3 - GiveWP Worker+ Stored XSS via Donation Form Template Settings
CVE.org
>=0, <4.16.3 v4.16.3 CVE-2026-14318 Jul 30, 2026

Data aggregated from WPVulnerability, NVD/NIST, ENISA EUVD, CVE.org and WordPress.org. Provided as-is; verify with the plugin author before acting. Disclaimer.