SecAlerts
G

GiveWP

Security Risk Profile

45
/100
medium

Security Risk Score

Comprehensive risk assessment based on 68 vulnerabilities, EPSS scores, exploitation status, and remediation availability.

📅 Data spans from March 21, 2019 to present

68
Total CVEs
25
Critical+High
1
Exploited
5
Unpatched

Threat Assessment

Avg CVSS
6.9
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
5
Critical/High
Risk Level
45/100
medium
⚠️ 1 Active Exploits🆕 2Fresh (<7d)📈 4 in Last 30 Days

Severity Distribution

Critical
13
High
12
Medium
41
Low
0

Exploit Likelihood

>50% chance
0
20-50%
0
5-20%
0
<5%
10

Age Distribution

Common Weaknesses (CWE)

1
XSS
25
2
CSRF
6
3
Infoleak
5
4
SQL Injection
3
5
SSRF
1

Most Affected Products

1. GiveWP GiveWP WordPress61
2. GiveWP Donation Plugin9
3. GiveWP GiveWP6
4. GiveWP Donation Plugin and Fundraising Platform5
5. GiveWP GiveWP WordPress Plugin3

Recent Vulnerabilities

See more →
bleepingcomputer-20260828181855
unknown

GiveWP WordPress donation plugin flaw lets hackers execute server commands

Aug 28, 2026⚠ Exploited🔧 No Patch
CVE-2026-5510
CVSS 6.4medium

GiveWP <= 4.14.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes

Aug 28, 2026🔧 No Patch
CVE-2026-14319
CVSS 7.5high

GiveWP < 4.16.3 - Unauthenticated Recurring Donor Information Disclosure

Jul 31, 2026🔧 No Patch
CVE-2026-14318
CVSS 6.8medium

GiveWP < 4.16.3 - GiveWP Worker+ Stored XSS via Donation Form Template Settings

Jul 30, 2026🔧 No Patch
CVE-2026-14987
CVSS 6.4medium

GiveWP <= 4.16.3 - Authenticated (Give Worker+) Stored Cross-Site Scripting via 'twitter_message' Sequoia Template Setting

Jul 16, 2026🔧 No Patch
CVE-2026-34900
CVSS 7.1high

WordPress GiveWP plugin <= 4.14.2 - Reflected Cross Site Scripting (XSS) vulnerability

Jun 15, 2026🔧 No Patch
CVE-2025-13206
CVSS 7.2high

GiveWP - Donation Plugin and Fundraising Platform <= 4.13.0 - Unauthenticated Stored Cross-Site Scripting via 'name'

Nov 19, 2025
CVE-2025-11228
CVSS 5.3medium

GiveWP – Donation Plugin and Fundraising Platform <= 4.10.0 - Missing Authorization to Unauthenticated Forms-Campaign Association

Oct 4, 2025
CVE-2025-11227
CVSS 6.5medium

GiveWP – Donation Plugin and Fundraising Platform <= 4.10.0 - Missing Authorization to Unauthenticated Forms and Campaigns Disclosure

Oct 4, 2025
CVE-2025-7221
CVSS 4.3medium

GiveWP – Donation Plugin and Fundraising Platform <= 4.5.0 - Missing Authorization to Donation Update

Aug 21, 2025

Monitor GiveWP in Real-Time

Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.

Powered bySecAlerts

Monitor Your Software Stack in Real-Time

Get instant alerts when vulnerabilities are discovered in your software stack. Stay ahead of security threats with SecAlerts.

© 2026 SecAlerts Pty Ltd. All rights reserved.