All 39 CVE vulnerabilities found in GiveWP – Donation Plugin and Fundraising Platform, with AI-generated Chinese analysis, references, and POCs.
This page catalogs known security weaknesses and vulnerabilities associated with GiveWP, a popular donation plugin and fundraising platform for WordPress. It aggregates data from vendor advisories, security researchers, and community reports to provide a comprehensive view of the product's security posture. The collection includes details on various weakness classes such as cross-site scripting, SQL injection, privilege escalation, and insecure direct object references. The time range covered spans from the plugin's early releases up to the most recent updates, ensuring historical context is available for trend analysis. Here, you can track GiveWP's security advisories as they are published, allowing you to stay informed about critical patches and fixes. You can also understand the nature of specific weakness classes affecting the platform, reviewing technical details and remediation steps for each reported issue. Additionally, this resource enables you to look up the full vulnerability history of GiveWP, helping developers and site administrators assess risk and prioritize maintenance tasks. By consolidating these scattered reports into a single accessible location, this page serves as a vital tool for maintaining the integrity and security of donation-based websites. Users can identify patterns in past vulnerabilities, evaluate the responsiveness of the development team, and make informed decisions about upgrading or configuring their instances. This information is essential for ensuring that sensitive donor data remains protected against emerging threats and known exploits.
Vendor: GiveWP
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2022-2260 | GiveWP < 2.21.3 - DoS via CSRF CWE-352 | 6.5 | - | 2022-08-01 |
| CVE-2022-2215 | GiveWP < 2.21.3 - Admin+ Stored Cross-Site Scripting CWE-79 | 4.8 | - | 2022-08-01 |
| CVE-2022-2117 | GiveWP – Donation Plugin and Fundraising Platform <= 2.20.2 - Sensitive Information Disclosure CWE-200 | 5.3 | Medium | 2022-07-18 |
| CVE-2022-0252 | Give < 2.17.3 - Reflected Cross-Site Scripting via Import Tool CWE-79 | 6.1 | - | 2022-02-21 |
| CVE-2021-25100 | Give < 2.17.3 - Reflected Cross-Site Scripting via Donation Forms Dashboard CWE-79 | 6.1 | - | 2022-02-21 |
| CVE-2021-25099 | Give < 2.17.3 - Unauthenticated Reflected Cross-Site Scripting CWE-79 | 6.1 | - | 2022-02-21 |
| CVE-2021-24524 | GiveWP < 2.12.0 - Authenticated Stored XSS CWE-79 | 4.8 | - | 2021-08-23 |
| CVE-2021-24315 | Give WP < 2.10.4 - Authenticated Stored Cross-Site Scripting (XSS) CWE-79 | 4.8 | - | 2021-05-17 |
| CVE-2021-24213 | GiveWP < 2.10.0 - Reflected Cross Site Scripting (XSS) CWE-79 | 6.1 | - | 2021-04-12 |
All 39 known CVE vulnerabilities affecting GiveWP – Donation Plugin and Fundraising Platform with full Chinese analysis, references, and POCs where available.