CVE-2025-2331: GiveWP – Donation Plugin and Fundraising Platform <= 3.22.1 - Authenticated (Subscriber+) Sensitive Information Exposure
The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.22.1 via a misconfigured capability check in the 'permissionsCheck' function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to extract sensitive data including reports detailing donors and donation amounts.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
GiveWP – Donation Plugin and Fundraising Platformto a version that resolves this vulnerability.Fixed in 3.22.1 - Compensating control
Restrict authenticated access to WordPress in a way that prevents Subscriber-level (and above) users from accessing GiveWP donation/reporting features or endpoints until the plugin is updated.
Event History
Frequently Asked Questions
What is the severity of CVE-2025-2331?
CVE-2025-2331 has a medium severity rating due to sensitive information exposure affecting users of the GiveWP donation plugin.
How do I fix CVE-2025-2331?
To fix CVE-2025-2331, update the GiveWP – Donation Plugin and Fundraising Platform to version 3.22.2 or later.
Who is affected by CVE-2025-2331?
Any users utilizing versions up to and including 3.22.1 of the GiveWP donation plugin are affected by CVE-2025-2331.
What type of vulnerability is CVE-2025-2331?
CVE-2025-2331 is classified as a Sensitive Information Exposure vulnerability due to improper capability checks.
Is CVE-2025-2331 a known issue in GiveWP?
Yes, CVE-2025-2331 is a recognized vulnerability that affects the GiveWP plugin in multiple versions prior to 3.22.2.