CVE-2025-4571: GiveWP – Donation Plugin and Fundraising Platform <= 4.3.0 - Missing Authorization To Authenticated (Contributor+) Campaign Data View And Modification
The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to unauthorized view and modification of data due to an insufficient capability check on the permissionsCheck functions in all versions up to, and including, 4.3.0. This makes it possible for authenticated attackers, with Contributor-level access and above, to view or delete fundraising campaigns, view donors' data, modify campaign events, etc.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2025-4571?
CVE-2025-4571 is classified as a critical vulnerability due to the potential for unauthorized data access and modification.
How do I fix CVE-2025-4571?
To fix CVE-2025-4571, update the GiveWP – Donation Plugin and Fundraising Platform to version 4.3.1 or later, which resolves the insufficient capability checks.
What versions are affected by CVE-2025-4571?
CVE-2025-4571 affects all versions of the GiveWP – Donation Plugin and Fundraising Platform up to and including version 4.3.0.
What kind of data could be compromised due to CVE-2025-4571?
Due to CVE-2025-4571, attackers could view and modify sensitive donor and campaign data within the plugin.
Who is impacted by CVE-2025-4571?
Users of the GiveWP – Donation Plugin and Fundraising Platform, especially those running versions up to 4.3.0, are impacted by CVE-2025-4571.