Pricing
Case studies
Login
Start trial
GiveWP
StellarWP
Developer
4.14.4
Latest version
100,000
Installations
No date
Last updated
WordPress Plugin
Active VDP
Report vulnerability
Vulnerabilities
Security Policy
Security Contributors
Vulnerability history
0 present
64 patched
29 Mitigation rules
WordPress GiveWP - Donation Plugin and Fundraising Platform plugin <= 3.14.1 - Unauthenticated PHP Object Injection to Remote Code Execution vulnerability
<= 3.14.1
02/02/2026
Arbitrary Shortocde Execution vulnerability
<= 4.13.1
08/01/2026
WordPress GiveWP - Donation plugin and Fundraising Platform plugin <= 4.6.0 - Unauthenticated Donor Data Exposure vulnerability
<= 4.6.0
31/12/2025
Unauthenticated PHP Object Injection vulnerability
<= 3.19.2
31/12/2025
Cross Site Request Forgery (CSRF) vulnerability
<= 4.13.1
23/12/2025
WordPress GiveWP - Donation plugin and Fundraising Platform plugin <= 4.13.0 - Unauthenticated Stored Cross-Site Scripting via 'name' vulnerability
<= 4.13.0
18/11/2025
Missing Authorization to Unauthenticated Forms and Campaigns Disclosure vulnerability
<= 4.10.0
03/10/2025
Missing Authorization to Unauthenticated Forms-Campaign Association vulnerability
<= 4.10.0
03/10/2025
Missing Authorization to Donation Update vulnerability
<= 4.5.0
20/08/2025
PII Sensitive Data Exposure vulnerability
< 4.6.1
01/08/2025
Authenticated (GiveWP worker+) Stored Cross-Site Scripting vulnerability
<= 4.5.0
30/07/2025
Missing Authorization To Authenticated (Contributor+) Campaign Data View And Modification vulnerability
<= 4.3.0
19/06/2025
Authenticated (Subscriber+) Sensitive Information Exposure vulnerability
<= 3.22.1
24/03/2025
Missing Authorization to Unauthenticated Arbitrary Earning Reports Disclosure via give_reports_earnings Function vulnerability
<= 3.22.0
18/03/2025
Unauthenticated PHP Object Injection vulnerability
<= 3.19.4
03/03/2025
PHP Object Injection vulnerability
<= 3.19.3
10/01/2025
Reflected XSS vulnerability
< 3.19.0
27/12/2024
Unauthenticated PHP Object Injection to Remote Code Execution vulnerability
<= 3.16.3
15/10/2024
Unauthenticated PHP Object Injection to Remote Code Execution (RCE) vulnerability
<= 3.16.1
30/09/2024
Authenticated (GiveWP Manager+) SQL Injection via order Parameter vulnerability
<= 3.16.1
27/09/2024
Cross Site Request Forgery (CSRF) vulnerability
<= 3.15.1
25/09/2024
Unauthenticated Full Path Disclosure vulnerability
<= 3.15.1
29/08/2024
Missing Authorization to Authenticated (Subscriber+) Limited File Deletion vulnerability
<= 3.14.1
20/08/2024
Missing Authorization to Unauthenticated Event Settings Update vulnerability
<= 3.13.0
20/08/2024
Missing Authorization to Limited Information Exposure vulnerability
<= 3.13.0
20/08/2024
Unauthenticated PHP Object Injection to Remote Code Execution (RCE) vulnerability
<= 3.14.1
09/08/2024
Insecure Direct Object Reference to Authenticated (GiveWP Worker+) Arbitrary Post Actions vulnerability
<= 3.13.0
19/07/2024
Reflected Cross Site Scripting (XSS) vulnerability
<= 3.12.0
06/06/2024
Authenticated (Contributor+) Stored Cross-Site Scripting vulnerability
<= 3.10.0
20/05/2024
Authenticated(Contributor+) Stored Cross-Site Scripting via Shortcode vulnerability
<= 3.6.1
15/04/2024
PHP Object Injection vulnerability
<= 3.4.2
26/03/2024
Authenticated (Contributor+) Stored Cross-Site Scripting vulnerability
<= 3.5.1
20/03/2024
Reflected Cross Site Scripting (XSS) vulnerability
<= 3.3.1
15/03/2024
Cross Site Scripting (XSS) vulnerability
<= 3.2.2
19/01/2024
Cross-Site Request Forgery (CSRF) to Stripe Integration Deletion vulnerability
<= 2.33.3
31/10/2023
Cross-Site Request Forgery (CSRF) to plugin installation vulnerability
<= 2.33.3
31/10/2023
Cross-Site Request Forgery (CSRF) to plugin deactivation vulnerability
<= 2.33.3
31/10/2023
Broken Access Control vulnerability
<= 2.33.1
31/10/2023
GiveWP Manager+ Privilege Escalation vulnerability
<= 2.33.0
04/09/2023
WordPress Give - Donation Plugin plugin <= 2.25.3 - PHP Object Injection vulnerability
<= 2.25.3
09/05/2023
Cross Site Request Forgery (CSRF) vulnerability
<= 2.25.2
27/03/2023
Cross Site Scripting (XSS) via render_dropdown vulnerability
<= 2.25.1
10/03/2023
Server Side Request Forgery (SSRF) vulnerability
<= 2.25.1
10/03/2023
CSV Injection vulnerability
<= 2.25.1
10/03/2023
Arbitrary Content Deletion vulnerability
<= 2.25.1
10/03/2023
Contributor+ Cross Site Scripting (XSS) vulnerability
<= 2.25.1
10/03/2023
Cross Site Request Forgery (CSRF) via give_cache_flush vulnerability
<= 2.25.1
10/03/2023
Unauthenticated SQL Injection Vulnerability
<= 2.23.2
18/01/2023
Authenticated Arbitrary File Read via Export function vulnerability
<= 2.20.2
12/07/2022
Authenticated Arbitrary File Creation via Export function vulnerability
<= 2.20.2
12/07/2022
DoS via Cross-Site Request Forgery (CSRF) vulnerability
<= 2.21.2
11/07/2022
Authenticated Stored Cross-Site Scripting (XSS) vulnerability
<= 2.21.2
11/07/2022
Reflected Cross-Site Scripting (XSS) vulnerability
<= 2.20.2
20/06/2022
Donor Information Disclosure vulnerability
<= 2.20.2
17/06/2022
Unauthenticated Reflected Cross-Site Scripting (XSS) vulnerability
<= 2.17.2
18/01/2022
Reflected Cross-Site Scripting (XSS) vulnerability
<= 2.17.2
18/01/2022
Reflected Cross-Site Scripting (XSS) vulnerability
<= 2.17.2
18/01/2022
Authenticated Stored Cross-Site Scripting (XSS) vulnerability
<= 2.11.3
26/07/2021
Authenticated Persistent Cross-Site Scripting (XSS) vulnerability
<= 2.10.1
21/04/2021
Reflected Cross-Site Scripting (XSS) vulnerability
<= 2.9.7
23/03/2021
Authentication Bypass
<= 2.5.4
26/09/2019
SQL Injection (SQLi) vulnerability
<= 2.5.0
12/08/2019
Reflected Cross-Site Scripting (XSS) vulnerability
<= 2.3.0
12/03/2019
Cross Site Scripting (XSS)
<= 0.8.4
20/04/2015