First published: Sat Mar 15 2025(Updated: )
The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the give_reports_earnings() function in all versions up to, and including, 3.22.0. This makes it possible for unauthenticated attackers to disclose sensitive information included within earnings reports.
Credit: security@wordfence.com
Affected Software | Affected Version | How to fix |
---|---|---|
GiveWP Donation Plugin | <=3.22.0 | |
Givenu Givenu Give | <3.22.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-2025 is considered a high severity vulnerability due to the potential for unauthorized data access.
To fix CVE-2025-2025, update the GiveWP – Donation Plugin and Fundraising Platform to version 3.22.1 or later.
Users of the GiveWP – Donation Plugin and Fundraising Platform version 3.22.0 and below are affected by CVE-2025-2025.
CVE-2025-2025 is an unauthorized access vulnerability resulting from a failure to implement proper capability checks.
Yes, CVE-2025-2025 can be exploited remotely by unauthenticated attackers, making it a critical concern.