The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 4.6.0. This makes it possible for unauthenticated attackers to extract donor names, emails, and donor id.
Metrics
Affected Vendors & Products
References
History
Wed, 06 Aug 2025 09:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 4.6.0. This makes it possible for unauthenticated attackers to extract donor names, emails, and donor id. | |
Title | GiveWP – Donation Plugin and Fundraising Platform <= 4.6.0 - Unauthenticated Donor Data Exposure | |
Weaknesses | CWE-200 | |
References |
|
|
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: Wordfence
Published: 2025-08-06T09:22:32.841Z
Updated: 2025-08-06T09:22:32.841Z
Reserved: 2025-08-05T20:29:49.881Z
Link: CVE-2025-8620

No data.

Status : Received
Published: 2025-08-06T10:15:35.967
Modified: 2025-08-06T10:15:35.967
Link: CVE-2025-8620

No data.