CVE-2025-11227

GiveWP – Donation Plugin and Fundraising Platform <= 4.10.0 - Missing Authorization to Unauthenticated Forms and Campaigns Disclosure

The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 4.10.0 via the 'registerGetForm', 'registerGetForms', 'registerGetCampaign' and 'registerGetCampaigns' functions due to a missing capability check. This makes it possible for unauthenticated attackers to extract data from private and draft donation forms, as well as archived campaigns.


We have discovered 12,458 live websites that are affected by CVE-2025-11227.

Run a Free Instant Scan




Affected Software

Product  GiveWP
Category Wordpress Plugins
Vulnerable Domains12,458 live websites (39% of GiveWP install base)
Vulnerable Versions
  • from 0 through 4.10
Vulnerable Versions Count234 versions ( 96% of all versions)


Common Weakness Enumeration

CWE-285 Improper Authorization



Details

  • Published - Oct 4, 2025
  • Updated - Oct 6, 2025

Credits

  • Rafshanzani Suhada (finder)

Website Distribution by Country

Number of websites using CVE-2025-11227
United States5,569 websites



Germany938 websites
GB779 websites
Italy673 websites
France586 websites
India334 websites
Canada315 websites
Spain241 websites
Australia233 websites
Cyprus205 websites

Website Distribution by TLD

Number of websites using CVE-2025-11227
.org5,127 websites
.com3,024 websites
.it443 websites
.de327 websites
.net216 websites
.org.uk211 websites
.fr173 websites
.ca173 websites
.co.uk154 websites
.nl104 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2025-11227

Top websites that are affected by CVE-2025-11227. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
****.info United States**,***
***********.org United States**,***
*********.org GB**,***
********.org United States**,***
************.org United States**,***
**************.com Australia**,***
******.info Italy**,***
****************.com United States***,***
**************.***.uk GB***,***
*****.org United States***,***
See full domain list

FAQ

CVE-2025-11227 is Improper Authorization in GiveWP
A total of 12,458 websites have been identified as vulnerable to CVE-2025-11227, based on global website indexing conducted by WebTechSurvey.
The GiveWP is affected by the CVE-2025-11227 vulnerability.
GiveWP versions up to and including 4.10 are vulnerable to CVE-2025-11227.