CVE-2025-8620: GiveWP – Donation Plugin and Fundraising Platform <= 4.6.0 - Unauthenticated Donor Data Exposure
The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 4.6.0. This makes it possible for unauthenticated attackers to extract donor names, emails, and donor id. CVE-2025-47444 is a duplicate of this issue. CVE-2025-47444 is a duplicate of this issue.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-8620?
CVE-2025-8620 is classified as a critical vulnerability due to the possibility of information exposure to unauthenticated attackers.
How do I fix CVE-2025-8620?
To fix CVE-2025-8620, update the GiveWP – Donation Plugin and Fundraising Platform to version 4.6.1 or later.
Which versions of the GiveWP plugin are affected by CVE-2025-8620?
All versions of the GiveWP – Donation Plugin and Fundraising Platform up to and including 4.6.0 are affected by CVE-2025-8620.
What kind of information can be exposed due to CVE-2025-8620?
CVE-2025-8620 allows unauthenticated attackers to extract sensitive donor information, including names, emails, and donor IDs.
Is authentication required to exploit CVE-2025-8620?
No, CVE-2025-8620 can be exploited by unauthenticated attackers, making it particularly dangerous.