Extension WordPress

Vulnérabilités GiveWP – Donation Plugin and Fundraising Platform

Cette page rassemble les failles publiées pour GiveWP – Donation Plugin and Fundraising Platform, leurs plages de versions affectées et les correctifs signalés dans la base locale.

89Vulnérabilités
9Critiques
89Avec correctif
10,0CVSS maximal

Historique de sécurité

CVE et vulnérabilités de GiveWP – Donation Plugin and Fundraising Platform

89 fiches

CVE-2026-82222 Critique · 9,8
GiveWP – Donation Plugin and Fundraising Platform

GiveWP – Donation Plugin and Fundraising Platform <= 4.16.7.1 – Unauthenticated PHP Object Injection to Remote Code Execution

The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 4.16.7.1 via unsafe handling of serialized donor account data during the legacy donation process.…

Versions affectées

*-4.16.7.1

Correctif

4.16.7.2

Publication

28/08/2026

CVE-2026-5510 Moyenne · 6,4
GiveWP – Donation Plugin and Fundraising Platform

GiveWP <= 4.14.4 – Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes

The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'give_form' shortcode in all versions up to, and including, 4.14.4. This is due to insufficient input sanitization and output…

Versions affectées

*-4.14.4

Correctif

4.14.5

Publication

27/08/2026

CVE-2026-73348 Moyenne · 5,3
GiveWP – Donation Plugin and Fundraising Platform

GiveWP – Donation Plugin and Fundraising Platform < 4.16.6 – Missing Authorization

The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to 4.16.6. This makes it possible for unauthenticated attackers to…

Versions affectées

[*, 4.16.6)

Correctif

4.16.6

Publication

14/08/2026

CVE-2026-73352 Moyenne · 5,3
GiveWP – Donation Plugin and Fundraising Platform

GiveWP – Donation Plugin and Fundraising Platform <= 4.16.5.1 – Missing Authorization

The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 4.16.5.1. This makes it possible for unauthenticated…

Versions affectées

*-4.16.5.1

Correctif

4.16.6

Publication

14/08/2026

CVE-2026-73349 Moyenne · 5,3
GiveWP – Donation Plugin and Fundraising Platform

GiveWP – Donation Plugin and Fundraising Platform < 4.16.6 – Missing Authorization

The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to 4.16.6. This makes it possible for unauthenticated attackers to…

Versions affectées

[*, 4.16.6)

Correctif

4.16.6

Publication

12/08/2026

CVE-2026-73357 Moyenne · 6,4
GiveWP – Donation Plugin and Fundraising Platform

GiveWP – Donation Plugin and Fundraising Platform < 4.16.6 – Authenticated (Donor+) Stored Cross-Site Scripting

The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to 4.16.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with…

Versions affectées

[*, 4.16.6)

Correctif

4.16.6

Publication

12/08/2026

CVE-2026-14317 Moyenne · 5,3
GiveWP – Donation Plugin and Fundraising Platform

GiveWP – Donation Plugin and Fundraising Platform < 4.16.3 – Unauthenticated Payment Bypass

The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Payment Bypass in all versions up to 4.16.3 (exclusive). This makes it possible for unauthenticated attackers to bypass payments.

Versions affectées

[*, 4.16.3)

Correctif

4.16.3

Publication

04/08/2026

CVE-2026-66690 Élevée · 7,2
GiveWP – Donation Plugin and Fundraising Platform

GiveWP – Donation Plugin and Fundraising Platform <= 4.16.5 – Unauthenticated Stored Cross-Site Scripting

The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.16.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated…

Versions affectées

*-4.16.5

Correctif

4.16.5.1

Publication

31/07/2026

CVE-2026-14318 Moyenne · 6,4
GiveWP – Donation Plugin and Fundraising Platform

GiveWP – Donation Plugin and Fundraising Platform < 4.16.3 – Authenticated (Custom role+) Stored Cross-Site Scripting

The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to 4.16.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with…

Versions affectées

[*, 4.16.3)

Correctif

4.16.3

Publication

30/07/2026

CVE-2026-65441 Élevée · 7,2
GiveWP – Donation Plugin and Fundraising Platform

GiveWP <= 4.16.3 – Unauthenticated Stored Cross-Site Scripting

The GiveWP plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.16.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts…

Versions affectées

*-4.16.3

Correctif

4.16.4

Publication

27/07/2026

CVE-2026-65464 Moyenne · 4,3
GiveWP – Donation Plugin and Fundraising Platform

GiveWP – Donation Plugin and Fundraising Platform <= 4.16.3 – Cross-Site Request Forgery

The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.16.3. This is due to missing or incorrect nonce validation on a function. This makes…

Versions affectées

*-4.16.3

Correctif

4.16.4

Publication

22/07/2026

CVE-2026-14987 Moyenne · 6,4
GiveWP – Donation Plugin and Fundraising Platform

GiveWP <= 4.16.3 – Authenticated (Give Worker+) Stored Cross-Site Scripting via 'twitter_message' Sequoia Template Setting

The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'twitter_message' Sequoia Template Setting in all versions up to, and including, 4.16.3 due to insufficient input sanitization and output escaping.…

Versions affectées

*-4.16.3

Correctif

4.16.4

Publication

15/07/2026

CVE-2026-14319 Moyenne · 5,3
GiveWP – Donation Plugin and Fundraising Platform

GiveWP <= 4.16.2 – Unauthenticated Recurring Donor Information Disclosure

The GiveWP plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 4.16.2. This is due to missing anonymity check in the subscription REST API endpoint allowing retrieval of anonymous donor subscription data…

Versions affectées

*-4.16.2

Correctif

4.16.3

Publication

13/07/2026

CVE-2026-13704 Moyenne · 6,4
GiveWP – Donation Plugin and Fundraising Platform

GiveWP <= 4.16.1 – Authenticated (Give Worker+) Stored Cross-Site Scripting via Sequioa Form

The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'sequoia[introduction][image]' parameter in all versions up to, and including, 4.16.1 due to insufficient input sanitization and output escaping. This…

Versions affectées

*-4.16.1

Correctif

4.16.2

Publication

01/07/2026

CVE-2026-11981 Moyenne · 4,3
GiveWP – Donation Plugin and Fundraising Platform

GiveWP <= 4.15.3 – Cross-Site Request Forgery

The GiveWP plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.15.3 This is due to missing nonce validation on the give_set_notification_status_handler() function. This makes it possible for unauthenticated attackers to disable…

Versions affectées

*-4.15.3

Correctif

4.15.4

Publication

30/06/2026

CVE-2026-13246 Moyenne · 6,4
GiveWP – Donation Plugin and Fundraising Platform

GiveWP <= 4.16.0 – Authenticated (Author+) Stored Cross-Site Scripting via 'block_id' Shortcode Attribute

The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'block_id' (and other) shortcode attributes of the 'givewp_campaign_comments' shortcode in versions up to, and including, 4.16.0. This is due…

Versions affectées

*-4.16.0

Correctif

4.16.1

Publication

30/06/2026

CVE-2026-42678 Élevée · 7,2
GiveWP – Donation Plugin and Fundraising Platform

GiveWP – Donation Plugin and Fundraising Platform <= 4.14.5 – Unauthenticated Stored Cross-Site Scripting

The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.14.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated…

Versions affectées

*-4.14.5

Correctif

4.14.6

Publication

16/05/2026

CVE-2026-34900 Moyenne · 6,1
GiveWP – Donation Plugin and Fundraising Platform

GiveWP – Donation Plugin and Fundraising Platform <= 4.14.2 – Reflected Cross-Site Scripting

The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 4.14.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated…

Versions affectées

*-4.14.2

Correctif

4.14.3

Publication

21/04/2026

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités