GiveWP Donation Plugin Sensitive Information Exposure Vulnerability

Vulnerability

A vulnerability allowing sensitive information exposure has been identified in the GiveWP Donation Plugin and Fundraising Platform for WordPress, affecting all versions through 3.22.1. The issue arises from a misconfigured capability check in the 'permissionsCheck' function, which allows authenticated attackers with Subscriber-level access and above to access sensitive data, including reports on donors and donation amounts.

Impact

Exploitation of this vulnerability could lead to unauthorized access to sensitive donor information and donation details.

Remediation

Users can update to GiveWP version 3.22.2 or a newer patched version to address this vulnerability.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
6.4
impact
0.6
exploitability
6.1
remediation
7.7
relevance
0.0
threat
3.2
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.