Browse all 12 CVE security advisories affecting GiveWP. AI-powered Chinese analysis, POCs, and references for each vulnerability.
GiveWP is a WordPress donation plugin enabling organizations to collect payments through various gateways. Historically, it has been susceptible to multiple remote code execution vulnerabilities, cross-site scripting (XSS), privilege escalations, and authentication bypasses. The plugin's 12 recorded CVEs highlight recurring issues in input validation, access control, and insecure deserialization. Notable incidents include multiple critical flaws allowing attackers to execute arbitrary code or compromise administrative accounts, often through insufficient sanitization of user inputs. Despite these vulnerabilities, GiveWP remains widely adopted, necessitating regular updates and careful configuration to mitigate security risks.
This page lists every published CVE security advisory associated with GiveWP. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.