Skip to content
Founder-led WordPress incident response and care Request an assessment
3zerodigital Request a Website Assessment

Plugin security history

GiveWP – Donation Plugin and Fundraising Platform Vulnerability History & Security Timeline

The Wordfence Intelligence dataset currently contains 79 vulnerability records associated with GiveWP – Donation Plugin and Fundraising Platform, published between 2015 and 2026.

Dataset last synchronized: 2026-08-02 09:41:47 UTC

At a glance

Security Snapshot

79Total records
8Critical
9High
61Medium
0Low
1Informational
79Patched records
0Currently marked unpatched
2015-04-20First disclosure
2026-07-27Latest disclosure
72 of 79CVE coverage

Year-by-Year Timeline

YearRecordsRelative volume
201511 records
201955 records
202133 records
202288 records
20232020 records
20241919 records
20251313 records
20261010 records

Severity Breakdown

SeverityRecordsShare
Critical810.1%
High911.4%
Medium6177.2%
Informational11.3%

Vulnerability-Type Breakdown

Cross-Site Scripting

28 records35.4%

First: 2015. Latest: 2026.

Missing Authorization

15 records19%

First: 2019. Latest: 2026.

CSRF

15 records19%

First: 2022. Latest: 2026.

Other

12 records15.2%

First: 2023. Latest: 2026.

Information Disclosure

4 records5.1%

First: 2022. Latest: 2025.

SQL Injection

3 records3.8%

First: 2019. Latest: 2024.

Path Traversal

1 record1.3%

First: 2022. Latest: 2022.

Privilege Escalation

1 record1.3%

First: 2023. Latest: 2023.

Patch Status

Patched
79
Currently marked unpatched
0
Unknown status
0

Patch status reflects the latest successfully synchronized source dataset and must be checked against the installed version.

Latest Known Patched Versions

  • 4.16.4
  • 4.16.2
  • 4.15.4
  • 4.16.1
  • 4.14.6
  • 4.14.3
  • 4.13.2
  • 4.13.1
  • 4.10.1
  • 4.6.1
  • 4.6.0
  • 4.3.1
  • 3.22.2
  • 3.22.1
  • 3.20.0
  • 3.19.3
  • 3.19.4
  • 3.19.0
  • 3.16.4
  • 3.16.2
  • 3.16.0
  • 3.14.2
  • 3.14.0
  • 3.12.1
  • 3.11.0
  • 3.5.0
  • 3.7.0
  • 3.6.0
  • 3.4.0
  • 3.3.0
  • 2.33.2
  • 2.33.4
  • 2.33.1
  • 2.26.0
  • 2.25.3
  • 2.25.2
  • 2.24
  • 2.21.0
  • 2.21.3
  • 2.17.3
  • 2.12.0
  • 2.10.4
  • 2.10.0
  • 2.5.10
  • 2.5.5
  • 2.5.1
  • 2.4.7
  • 2.3.1
  • 0.8.5

Affected-Version History

Ranges are deduplicated by source range record and shown with the associated disclosure and known patched versions.

Affected rangeVulnerabilityPublishedPatched versionSeverity
*-3.16.1GiveWP – Donation Plugin and Fundraising Platform <= 3.16.1 - Unauthenticated PHP Object InjectionSeptember 27, 20243.16.2Critical
*-3.16.1GiveWP – Donation Plugin and Fundraising Platform <= 3.16.1 - Authenticated (GiveWP Manager+) SQL Injection via order ParameterSeptember 26, 20243.16.2High
*-3.15.1GiveWP <= 3.15.1 - Cross-Site Request ForgerySeptember 25, 20243.16.0Medium
*-3.15.1GiveWP <= 3.15.1 - Unauthenticated Full Path DisclosureAugust 28, 20243.16.0Medium
*-3.14.1GiveWP – Donation Plugin and Fundraising Platform <= 3.14.1 - Unauthenticated PHP Object Injection to Remote Code ExecutionAugust 19, 20243.14.2Critical
*-3.13.0GiveWP – Donation Plugin and Fundraising Platform <= 3.13.0 - Missing Authorization to Unauthenticated Event Settings UpdateAugust 19, 20243.14.0Medium
*-3.13.0GiveWP – Donation Plugin and Fundraising Platform <= 3.13.0 - Missing Authorization to Limited Information ExposureAugust 19, 20243.14.0Medium
*-3.14.1GiveWP – Donation Plugin and Fundraising Platform <= 3.14.1 - Missing Authorization to Authenticated (Subscriber+) Limited File DeletionAugust 19, 20243.14.2Medium
*-3.14.1GiveWP <= 3.14.1 - Unauthenticated PHP Object InjectionAugust 9, 20243.14.2High
*-3.13.0GiveWP – Donation Plugin and Fundraising Platform <= 3.13.0 - Insecure Direct Object Reference to Authenticated (GiveWP Worker+) Arbitrary Post ActionsJuly 18, 20243.14.0Medium
*-3.12.0GiveWP – Donation Plugin and Fundraising Platform <= 3.12.0 - Reflected Cross-Site ScriptingJune 6, 20243.12.1Medium
*-3.10.0GiveWP – Donation Plugin and Fundraising Platform <= 3.10.0 - Authenticated (Contributor+) Stored Cross-Site ScriptingMay 17, 20243.11.0Medium
*-3.4.2GiveWP – Donation Plugin and Fundraising Platform <= 3.4.2 - Authenticated (GiveWP Manager+) PHP Object InjectionApril 26, 20243.5.0High
*-3.6.1GiveWP – Donation Plugin and Fundraising Platform <= 3.6.1 -- Authenticated(Contributor+) Stored Cross-Site Scripting via ShortcodeApril 12, 20243.7.0Medium
*-3.5.1GiveWP – Donation Plugin and Fundraising Platform <= 3.5.1 - Authenticated (Contributor+) Stored Cross-Site ScriptingMarch 19, 20243.6.0Medium
*-3.3.1GiveWP <= 3.3.1 - Reflected Cross-Site ScriptingMarch 15, 20243.4.0Medium
*-3.2.2GiveWP <= 3.2.2 - Authenticated (Contributor+) Stored Cross-Site ScriptingJanuary 19, 20243.3.0Medium
*-2.33.3GiveWP <= 2.33.3 - Cross-Site Request Forgery to plugin deactivationOctober 31, 20232.33.4Medium
*-2.33.3GiveWP <= 2.33.3 - Cross-Site Request Forgery to plugin installationOctober 31, 20232.33.4Medium
*-2.33.1GiveWP <= 2.33.1 - Missing Authorization via handleBeforeGatewayOctober 31, 20232.33.2Medium
*-2.33.3GiveWP <= 2.33.3 - Cross-Site Request Forgery to Stripe Integration DeletionOctober 31, 20232.33.4Medium
[*, 2.33.1)Give - Donation Plugin <= 2.33.0 - Authenticated(Give Manager+) Privilege EscalationAugust 31, 20232.33.1High
*-2.25.3GiveWP <= 2.25.3 - Authenticated (Admin+) PHP Object InjectionMay 10, 20232.26.0Medium
*-2.25.2GiveWP <= 2.25.2 - Cross-Site Request Forgery via give_ajax_store_payment_noteMarch 23, 20232.25.3Medium
*-2.25.2GiveWP <= 2.25.2 - Cross-Site Request Forgery via give_ajax_delete_payment_noteMarch 23, 20232.25.3Medium

Selected source records

Latest Records

HighCVE-2026-65441

GiveWP <= 4.16.3 - Unauthenticated Stored Cross-Site Scripting

Published: July 27, 2026

Affected versions
*-4.16.3
Patched versions
4.16.4
Original Wordfence record
MediumCVE-2026-65464

GiveWP – Donation Plugin and Fundraising Platform <= 4.16.3 - Cross-Site Request Forgery

Published: July 22, 2026

Affected versions
*-4.16.3
Patched versions
4.16.4
Original Wordfence record
MediumCVE-2026-14987

GiveWP <= 4.16.3 - Authenticated (Give Worker+) Stored Cross-Site Scripting via 'twitter_message' Sequoia Template Setting

Published: July 15, 2026

Affected versions
*-4.16.3
Patched versions
4.16.4
Original Wordfence record
MediumCVE-2026-13704

GiveWP <= 4.16.1 - Authenticated (Give Worker+) Stored Cross-Site Scripting via Sequioa Form

Published: July 1, 2026

Affected versions
*-4.16.1
Patched versions
4.16.2
Original Wordfence record
MediumCVE-2026-11981

GiveWP <= 4.15.3 - Cross-Site Request Forgery

Published: June 30, 2026

Affected versions
*-4.15.3
Patched versions
4.15.4
Original Wordfence record
MediumCVE-2026-13246

GiveWP <= 4.16.0 - Authenticated (Author+) Stored Cross-Site Scripting via 'block_id' Shortcode Attribute

Published: June 30, 2026

Affected versions
*-4.16.0
Patched versions
4.16.1
Original Wordfence record
HighCVE-2026-42678

GiveWP – Donation Plugin and Fundraising Platform <= 4.14.5 - Unauthenticated Stored Cross-Site Scripting

Published: May 16, 2026

Affected versions
*-4.14.5
Patched versions
4.14.6
Original Wordfence record
MediumCVE-2026-34900

GiveWP – Donation Plugin and Fundraising Platform <= 4.14.2 - Reflected Cross-Site Scripting

Published: April 21, 2026

Affected versions
*-4.14.2
Patched versions
4.14.3
Original Wordfence record

Highest-Severity Records

CriticalCVE-2024-5932

GiveWP – Donation Plugin and Fundraising Platform <= 3.14.1 - Unauthenticated PHP Object Injection to Remote Code Execution

Published: August 19, 2024

Affected versions
*-3.14.1
Patched versions
3.14.2
Original Wordfence record
CriticalCVE-2025-22777

GiveWP – Donation Plugin and Fundraising Platform <= 3.19.3 - Unauthenticated PHP Object Injection

Published: January 10, 2025

Affected versions
*-3.19.3
Patched versions
3.19.4
Original Wordfence record
CriticalCVE-2019-13578

GiveWP - Donation Plugin and Fundraising Platform <= 2.5.0 - SQL Injection

Published: August 12, 2019

Affected versions
*-2.5.0
Patched versions
2.5.1
Original Wordfence record
CriticalCVE-2023-0224

GiveWP <= 2.23.2 - Unauthenticated SQL Injection

Published: January 19, 2023

Affected versions
*-2.23.2
Patched versions
2.24
Original Wordfence record
CriticalCVE-2025-0912

GiveWP – Donation Plugin and Fundraising Platform <= 3.19.4 - Unauthenticated PHP Object Injection

Published: March 3, 2025

Affected versions
*-3.19.4
Patched versions
3.20.0
Original Wordfence record
CriticalCVE-2024-12877

GiveWP – Donation Plugin and Fundraising Platform <= 3.19.2 - Unauthenticated PHP Object Injection

Published: January 10, 2025

Affected versions
*-3.19.2
Patched versions
3.19.3
Original Wordfence record
CriticalCVE-2024-9634

GiveWP – Donation Plugin and Fundraising Platform <= 3.16.3 - Unauthenticated PHP Object Injection to Remote Code Execution

Published: October 15, 2024

Affected versions
*-3.16.3
Patched versions
3.16.4
Original Wordfence record
CriticalCVE-2024-8353

GiveWP – Donation Plugin and Fundraising Platform <= 3.16.1 - Unauthenticated PHP Object Injection

Published: September 27, 2024

Affected versions
*-3.16.1
Patched versions
3.16.2
Original Wordfence record

View all associated vulnerabilities

Need help reviewing an exposed WordPress website?

Running an affected version does not prove that a website was compromised. Suspicious redirects, unknown administrators, injected content, unexpected files or recurring malware may require a manual investigation.

Vulnerability data: Wordfence Intelligence. Analysis and practical guidance: 3Zero Digital.

Data Source, Attribution and Methodology

This page aggregates active Production Feed records. Counts are not software-quality rankings, and an affected version does not prove exploitation or infection. Read the full methodology.

Return to the Security History Directory