Skip to content
Founder-led WordPress incident response and care Request an assessment
3zerodigital Request a Website Assessment

Plugin security history

GiveWP – Donation Plugin and Fundraising Platform Vulnerability History & Security Timeline

The Wordfence Intelligence dataset currently contains 79 vulnerability records associated with GiveWP – Donation Plugin and Fundraising Platform, published between 2015 and 2026.

Dataset last synchronized: 2026-08-02 09:41:47 UTC

At a glance

Security Snapshot

79Total records
8Critical
9High
61Medium
0Low
1Informational
79Patched records
0Currently marked unpatched
2015-04-20First disclosure
2026-07-27Latest disclosure
72 of 79CVE coverage

Year-by-Year Timeline

YearRecordsRelative volume
201511 records
201955 records
202133 records
202288 records
20232020 records
20241919 records
20251313 records
20261010 records

Severity Breakdown

SeverityRecordsShare
Critical810.1%
High911.4%
Medium6177.2%
Informational11.3%

Vulnerability-Type Breakdown

Cross-Site Scripting

28 records35.4%

First: 2015. Latest: 2026.

Missing Authorization

15 records19%

First: 2019. Latest: 2026.

CSRF

15 records19%

First: 2022. Latest: 2026.

Other

12 records15.2%

First: 2023. Latest: 2026.

Information Disclosure

4 records5.1%

First: 2022. Latest: 2025.

SQL Injection

3 records3.8%

First: 2019. Latest: 2024.

Path Traversal

1 record1.3%

First: 2022. Latest: 2022.

Privilege Escalation

1 record1.3%

First: 2023. Latest: 2023.

Patch Status

Patched
79
Currently marked unpatched
0
Unknown status
0

Patch status reflects the latest successfully synchronized source dataset and must be checked against the installed version.

Latest Known Patched Versions

  • 4.16.4
  • 4.16.2
  • 4.15.4
  • 4.16.1
  • 4.14.6
  • 4.14.3
  • 4.13.2
  • 4.13.1
  • 4.10.1
  • 4.6.1
  • 4.6.0
  • 4.3.1
  • 3.22.2
  • 3.22.1
  • 3.20.0
  • 3.19.3
  • 3.19.4
  • 3.19.0
  • 3.16.4
  • 3.16.2
  • 3.16.0
  • 3.14.2
  • 3.14.0
  • 3.12.1
  • 3.11.0
  • 3.5.0
  • 3.7.0
  • 3.6.0
  • 3.4.0
  • 3.3.0
  • 2.33.2
  • 2.33.4
  • 2.33.1
  • 2.26.0
  • 2.25.3
  • 2.25.2
  • 2.24
  • 2.21.0
  • 2.21.3
  • 2.17.3
  • 2.12.0
  • 2.10.4
  • 2.10.0
  • 2.5.10
  • 2.5.5
  • 2.5.1
  • 2.4.7
  • 2.3.1
  • 0.8.5

Affected-Version History

Ranges are deduplicated by source range record and shown with the associated disclosure and known patched versions.

Affected rangeVulnerabilityPublishedPatched versionSeverity
*-4.16.3GiveWP <= 4.16.3 - Unauthenticated Stored Cross-Site ScriptingJuly 27, 20264.16.4High
*-4.16.3GiveWP – Donation Plugin and Fundraising Platform <= 4.16.3 - Cross-Site Request ForgeryJuly 22, 20264.16.4Medium
*-4.16.3GiveWP <= 4.16.3 - Authenticated (Give Worker+) Stored Cross-Site Scripting via 'twitter_message' Sequoia Template SettingJuly 15, 20264.16.4Medium
*-4.16.1GiveWP <= 4.16.1 - Authenticated (Give Worker+) Stored Cross-Site Scripting via Sequioa FormJuly 1, 20264.16.2Medium
*-4.15.3GiveWP <= 4.15.3 - Cross-Site Request ForgeryJune 30, 20264.15.4Medium
*-4.16.0GiveWP <= 4.16.0 - Authenticated (Author+) Stored Cross-Site Scripting via 'block_id' Shortcode AttributeJune 30, 20264.16.1Medium
*-4.14.5GiveWP – Donation Plugin and Fundraising Platform <= 4.14.5 - Unauthenticated Stored Cross-Site ScriptingMay 16, 20264.14.6High
*-4.14.2GiveWP – Donation Plugin and Fundraising Platform <= 4.14.2 - Reflected Cross-Site ScriptingApril 21, 20264.14.3Medium
*-4.14.5GiveWP <= 4.14.5 - Missing AuthorizationMarch 2, 20264.14.6Medium
*-4.13.1GiveWP <= 4.13.1 - Unauthenticated Arbitrary Shortcode ExecutionJanuary 8, 20264.13.2Medium
*-4.13.1GiveWP <= 4.13.1 - Cross-Site Request ForgeryDecember 23, 20254.13.2Medium
*-4.13.0GiveWP - Donation Plugin and Fundraising Platform <= 4.13.0 - Unauthenticated Stored Cross-Site Scripting via 'name'November 18, 20254.13.1High
*-4.10.0GiveWP – Donation Plugin and Fundraising Platform <= 4.10.0 - Missing Authorization to Unauthenticated Forms and Campaigns DisclosureOctober 3, 20254.10.1Medium
*-4.10.0GiveWP – Donation Plugin and Fundraising Platform <= 4.10.0 - Missing Authorization to Unauthenticated Forms-Campaign AssociationOctober 3, 20254.10.1Medium
*-4.5.0GiveWP – Donation Plugin and Fundraising Platform <= 4.5.0 - Missing Authorization to Donation UpdateAugust 20, 20254.6.1Medium
*-4.6.0GiveWP – Donation Plugin and Fundraising Platform <= 4.6.0 - Unauthenticated Donor Data ExposureAugust 5, 20254.6.1Medium
*-4.5.0GiveWP – Donation Plugin and Fundraising Platform <= 4.5.0 - Authenticated (GiveWP worker+) Stored Cross-Site ScriptingJuly 30, 20254.6.0Medium
*-4.3.0GiveWP – Donation Plugin and Fundraising Platform <= 4.3.0 - Missing Authorization To Authenticated (Contributor+) Campaign Data View And ModificationJune 18, 20254.3.1Medium
*-3.22.1GiveWP – Donation Plugin and Fundraising Platform <= 3.22.1 - Authenticated (Subscriber+) Sensitive Information ExposureMarch 21, 20253.22.2Medium
*-3.22.0Give <= 3.22.0 - Missing Authorization to Unauthenticated Arbitrary Earning Reports Disclosure via give_reports_earnings FunctionMarch 14, 20253.22.1Medium
*-3.19.4GiveWP – Donation Plugin and Fundraising Platform <= 3.19.4 - Unauthenticated PHP Object InjectionMarch 3, 20253.20.0Critical
*-3.19.2GiveWP – Donation Plugin and Fundraising Platform <= 3.19.2 - Unauthenticated PHP Object InjectionJanuary 10, 20253.19.3Critical
*-3.19.3GiveWP – Donation Plugin and Fundraising Platform <= 3.19.3 - Unauthenticated PHP Object InjectionJanuary 10, 20253.19.4Critical
*-3.18.0GiveWP – Donation Plugin and Fundraising Platform <= 3.18.0 - Reflected Cross-Site ScriptingDecember 6, 20243.19.0Medium
*-3.16.3GiveWP – Donation Plugin and Fundraising Platform <= 3.16.3 - Unauthenticated PHP Object Injection to Remote Code ExecutionOctober 15, 20243.16.4Critical

Selected source records

Latest Records

HighCVE-2026-65441

GiveWP <= 4.16.3 - Unauthenticated Stored Cross-Site Scripting

Published: July 27, 2026

Affected versions
*-4.16.3
Patched versions
4.16.4
Original Wordfence record
MediumCVE-2026-65464

GiveWP – Donation Plugin and Fundraising Platform <= 4.16.3 - Cross-Site Request Forgery

Published: July 22, 2026

Affected versions
*-4.16.3
Patched versions
4.16.4
Original Wordfence record
MediumCVE-2026-14987

GiveWP <= 4.16.3 - Authenticated (Give Worker+) Stored Cross-Site Scripting via 'twitter_message' Sequoia Template Setting

Published: July 15, 2026

Affected versions
*-4.16.3
Patched versions
4.16.4
Original Wordfence record
MediumCVE-2026-13704

GiveWP <= 4.16.1 - Authenticated (Give Worker+) Stored Cross-Site Scripting via Sequioa Form

Published: July 1, 2026

Affected versions
*-4.16.1
Patched versions
4.16.2
Original Wordfence record
MediumCVE-2026-11981

GiveWP <= 4.15.3 - Cross-Site Request Forgery

Published: June 30, 2026

Affected versions
*-4.15.3
Patched versions
4.15.4
Original Wordfence record
MediumCVE-2026-13246

GiveWP <= 4.16.0 - Authenticated (Author+) Stored Cross-Site Scripting via 'block_id' Shortcode Attribute

Published: June 30, 2026

Affected versions
*-4.16.0
Patched versions
4.16.1
Original Wordfence record
HighCVE-2026-42678

GiveWP – Donation Plugin and Fundraising Platform <= 4.14.5 - Unauthenticated Stored Cross-Site Scripting

Published: May 16, 2026

Affected versions
*-4.14.5
Patched versions
4.14.6
Original Wordfence record
MediumCVE-2026-34900

GiveWP – Donation Plugin and Fundraising Platform <= 4.14.2 - Reflected Cross-Site Scripting

Published: April 21, 2026

Affected versions
*-4.14.2
Patched versions
4.14.3
Original Wordfence record

Highest-Severity Records

CriticalCVE-2024-5932

GiveWP – Donation Plugin and Fundraising Platform <= 3.14.1 - Unauthenticated PHP Object Injection to Remote Code Execution

Published: August 19, 2024

Affected versions
*-3.14.1
Patched versions
3.14.2
Original Wordfence record
CriticalCVE-2025-22777

GiveWP – Donation Plugin and Fundraising Platform <= 3.19.3 - Unauthenticated PHP Object Injection

Published: January 10, 2025

Affected versions
*-3.19.3
Patched versions
3.19.4
Original Wordfence record
CriticalCVE-2019-13578

GiveWP - Donation Plugin and Fundraising Platform <= 2.5.0 - SQL Injection

Published: August 12, 2019

Affected versions
*-2.5.0
Patched versions
2.5.1
Original Wordfence record
CriticalCVE-2023-0224

GiveWP <= 2.23.2 - Unauthenticated SQL Injection

Published: January 19, 2023

Affected versions
*-2.23.2
Patched versions
2.24
Original Wordfence record
CriticalCVE-2025-0912

GiveWP – Donation Plugin and Fundraising Platform <= 3.19.4 - Unauthenticated PHP Object Injection

Published: March 3, 2025

Affected versions
*-3.19.4
Patched versions
3.20.0
Original Wordfence record
CriticalCVE-2024-12877

GiveWP – Donation Plugin and Fundraising Platform <= 3.19.2 - Unauthenticated PHP Object Injection

Published: January 10, 2025

Affected versions
*-3.19.2
Patched versions
3.19.3
Original Wordfence record
CriticalCVE-2024-9634

GiveWP – Donation Plugin and Fundraising Platform <= 3.16.3 - Unauthenticated PHP Object Injection to Remote Code Execution

Published: October 15, 2024

Affected versions
*-3.16.3
Patched versions
3.16.4
Original Wordfence record
CriticalCVE-2024-8353

GiveWP – Donation Plugin and Fundraising Platform <= 3.16.1 - Unauthenticated PHP Object Injection

Published: September 27, 2024

Affected versions
*-3.16.1
Patched versions
3.16.2
Original Wordfence record

View all associated vulnerabilities

Need help reviewing an exposed WordPress website?

Running an affected version does not prove that a website was compromised. Suspicious redirects, unknown administrators, injected content, unexpected files or recurring malware may require a manual investigation.

Vulnerability data: Wordfence Intelligence. Analysis and practical guidance: 3Zero Digital.

Data Source, Attribution and Methodology

This page aggregates active Production Feed records. Counts are not software-quality rankings, and an affected version does not prove exploitation or infection. Read the full methodology.

Return to the Security History Directory