Skip to content
Founder-led WordPress incident response and care Request an assessment
3zerodigital Request a Website Assessment

Plugin security history

GiveWP – Donation Plugin and Fundraising Platform Vulnerability History & Security Timeline

The Wordfence Intelligence dataset currently contains 79 vulnerability records associated with GiveWP – Donation Plugin and Fundraising Platform, published between 2015 and 2026.

Dataset last synchronized: 2026-08-02 09:41:47 UTC

At a glance

Security Snapshot

79Total records
8Critical
9High
61Medium
0Low
1Informational
79Patched records
0Currently marked unpatched
2015-04-20First disclosure
2026-07-27Latest disclosure
72 of 79CVE coverage

Year-by-Year Timeline

YearRecordsRelative volume
201511 records
201955 records
202133 records
202288 records
20232020 records
20241919 records
20251313 records
20261010 records

Severity Breakdown

SeverityRecordsShare
Critical810.1%
High911.4%
Medium6177.2%
Informational11.3%

Vulnerability-Type Breakdown

Cross-Site Scripting

28 records35.4%

First: 2015. Latest: 2026.

Missing Authorization

15 records19%

First: 2019. Latest: 2026.

CSRF

15 records19%

First: 2022. Latest: 2026.

Other

12 records15.2%

First: 2023. Latest: 2026.

Information Disclosure

4 records5.1%

First: 2022. Latest: 2025.

SQL Injection

3 records3.8%

First: 2019. Latest: 2024.

Path Traversal

1 record1.3%

First: 2022. Latest: 2022.

Privilege Escalation

1 record1.3%

First: 2023. Latest: 2023.

Patch Status

Patched
79
Currently marked unpatched
0
Unknown status
0

Patch status reflects the latest successfully synchronized source dataset and must be checked against the installed version.

Latest Known Patched Versions

  • 4.16.4
  • 4.16.2
  • 4.15.4
  • 4.16.1
  • 4.14.6
  • 4.14.3
  • 4.13.2
  • 4.13.1
  • 4.10.1
  • 4.6.1
  • 4.6.0
  • 4.3.1
  • 3.22.2
  • 3.22.1
  • 3.20.0
  • 3.19.3
  • 3.19.4
  • 3.19.0
  • 3.16.4
  • 3.16.2
  • 3.16.0
  • 3.14.2
  • 3.14.0
  • 3.12.1
  • 3.11.0
  • 3.5.0
  • 3.7.0
  • 3.6.0
  • 3.4.0
  • 3.3.0
  • 2.33.2
  • 2.33.4
  • 2.33.1
  • 2.26.0
  • 2.25.3
  • 2.25.2
  • 2.24
  • 2.21.0
  • 2.21.3
  • 2.17.3
  • 2.12.0
  • 2.10.4
  • 2.10.0
  • 2.5.10
  • 2.5.5
  • 2.5.1
  • 2.4.7
  • 2.3.1
  • 0.8.5

Affected-Version History

Ranges are deduplicated by source range record and shown with the associated disclosure and known patched versions.

Affected rangeVulnerabilityPublishedPatched versionSeverity
*-2.5.0GiveWP - Donation Plugin and Fundraising Platform <= 2.5.0 - SQL InjectionAugust 12, 20192.5.1Critical
[*, 2.4.7)GiveWP <= 2.4.6 - Cross-Site ScriptingMay 15, 20192.4.7Medium
[*, 2.3.1)GiveWP <= 2.3.0 - Cross-Site ScriptingFebruary 5, 20192.3.1Medium
[*, 0.8.5)GiveWP – Donation Plugin and Fundraising Platform < 0.8.5 - Reflected Cross-Site ScriptingApril 20, 20150.8.5Medium

Selected source records

Latest Records

HighCVE-2026-65441

GiveWP <= 4.16.3 - Unauthenticated Stored Cross-Site Scripting

Published: July 27, 2026

Affected versions
*-4.16.3
Patched versions
4.16.4
Original Wordfence record
MediumCVE-2026-65464

GiveWP – Donation Plugin and Fundraising Platform <= 4.16.3 - Cross-Site Request Forgery

Published: July 22, 2026

Affected versions
*-4.16.3
Patched versions
4.16.4
Original Wordfence record
MediumCVE-2026-14987

GiveWP <= 4.16.3 - Authenticated (Give Worker+) Stored Cross-Site Scripting via 'twitter_message' Sequoia Template Setting

Published: July 15, 2026

Affected versions
*-4.16.3
Patched versions
4.16.4
Original Wordfence record
MediumCVE-2026-13704

GiveWP <= 4.16.1 - Authenticated (Give Worker+) Stored Cross-Site Scripting via Sequioa Form

Published: July 1, 2026

Affected versions
*-4.16.1
Patched versions
4.16.2
Original Wordfence record
MediumCVE-2026-11981

GiveWP <= 4.15.3 - Cross-Site Request Forgery

Published: June 30, 2026

Affected versions
*-4.15.3
Patched versions
4.15.4
Original Wordfence record
MediumCVE-2026-13246

GiveWP <= 4.16.0 - Authenticated (Author+) Stored Cross-Site Scripting via 'block_id' Shortcode Attribute

Published: June 30, 2026

Affected versions
*-4.16.0
Patched versions
4.16.1
Original Wordfence record
HighCVE-2026-42678

GiveWP – Donation Plugin and Fundraising Platform <= 4.14.5 - Unauthenticated Stored Cross-Site Scripting

Published: May 16, 2026

Affected versions
*-4.14.5
Patched versions
4.14.6
Original Wordfence record
MediumCVE-2026-34900

GiveWP – Donation Plugin and Fundraising Platform <= 4.14.2 - Reflected Cross-Site Scripting

Published: April 21, 2026

Affected versions
*-4.14.2
Patched versions
4.14.3
Original Wordfence record

Highest-Severity Records

CriticalCVE-2024-5932

GiveWP – Donation Plugin and Fundraising Platform <= 3.14.1 - Unauthenticated PHP Object Injection to Remote Code Execution

Published: August 19, 2024

Affected versions
*-3.14.1
Patched versions
3.14.2
Original Wordfence record
CriticalCVE-2025-22777

GiveWP – Donation Plugin and Fundraising Platform <= 3.19.3 - Unauthenticated PHP Object Injection

Published: January 10, 2025

Affected versions
*-3.19.3
Patched versions
3.19.4
Original Wordfence record
CriticalCVE-2019-13578

GiveWP - Donation Plugin and Fundraising Platform <= 2.5.0 - SQL Injection

Published: August 12, 2019

Affected versions
*-2.5.0
Patched versions
2.5.1
Original Wordfence record
CriticalCVE-2023-0224

GiveWP <= 2.23.2 - Unauthenticated SQL Injection

Published: January 19, 2023

Affected versions
*-2.23.2
Patched versions
2.24
Original Wordfence record
CriticalCVE-2025-0912

GiveWP – Donation Plugin and Fundraising Platform <= 3.19.4 - Unauthenticated PHP Object Injection

Published: March 3, 2025

Affected versions
*-3.19.4
Patched versions
3.20.0
Original Wordfence record
CriticalCVE-2024-12877

GiveWP – Donation Plugin and Fundraising Platform <= 3.19.2 - Unauthenticated PHP Object Injection

Published: January 10, 2025

Affected versions
*-3.19.2
Patched versions
3.19.3
Original Wordfence record
CriticalCVE-2024-9634

GiveWP – Donation Plugin and Fundraising Platform <= 3.16.3 - Unauthenticated PHP Object Injection to Remote Code Execution

Published: October 15, 2024

Affected versions
*-3.16.3
Patched versions
3.16.4
Original Wordfence record
CriticalCVE-2024-8353

GiveWP – Donation Plugin and Fundraising Platform <= 3.16.1 - Unauthenticated PHP Object Injection

Published: September 27, 2024

Affected versions
*-3.16.1
Patched versions
3.16.2
Original Wordfence record

View all associated vulnerabilities

Need help reviewing an exposed WordPress website?

Running an affected version does not prove that a website was compromised. Suspicious redirects, unknown administrators, injected content, unexpected files or recurring malware may require a manual investigation.

Vulnerability data: Wordfence Intelligence. Analysis and practical guidance: 3Zero Digital.

Data Source, Attribution and Methodology

This page aggregates active Production Feed records. Counts are not software-quality rankings, and an affected version does not prove exploitation or infection. Read the full methodology.

Return to the Security History Directory