CVE-2025-66533: WordPress GiveWP plugin <= 4.13.1 - Arbitrary Shortocde Execution vulnerability
Published Dec 9, 2025
·Updated
Improper Control of Generation of Code ('Code Injection') vulnerability in StellarWP GiveWP give allows Code Injection.This issue affects GiveWP: from n/a through <= 4.13.1.
Affected Software
1 affected component
wordpress/givewp<=4.13.1
Event History
Dec 9, 2025
CVE Published
via MITRE·03:03 PM
Data Sourced
via MITRE·03:03 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:18 PM
DescriptionSeverityWeakness
Nov 30, 58290
Event
via MITRE·03:17 PM
Frequently Asked Questions
1
What is the severity of CVE-2025-66533?
CVE-2025-66533 is classified as a critical severity vulnerability due to its ability to allow code injection in affected versions of GiveWP.
2
How do I fix CVE-2025-66533?
To mitigate CVE-2025-66533, upgrade the GiveWP plugin to a version greater than 4.13.1.
3
Which versions of GiveWP are affected by CVE-2025-66533?
CVE-2025-66533 affects all GiveWP versions from n/a through 4.13.1.
4
What type of vulnerability is CVE-2025-66533?
CVE-2025-66533 is an improper control of generation of code vulnerability leading to code injection.
5
Can CVE-2025-66533 lead to remote code execution?
Yes, CVE-2025-66533 can potentially allow remote code execution due to its code injection capabilities.