The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 4.10.0 via the 'registerGetForm', 'registerGetForms', 'registerGetCampaign' and 'registerGetCampaigns' functions due to a missing capability check. This makes it possible for unauthenticated attackers to extract data from private and draft donation forms, as well as archived campaigns.
We have discovered 12,458 live websites that are affected by CVE-2025-11227.
| Product | |
| Category | Wordpress Plugins |
| Vulnerable Domains | 12,458 live websites (39% of GiveWP install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 234 versions ( 96% of all versions) |
| 5,569 websites | |
| 938 websites | |
| 779 websites | |
| 673 websites | |
| 586 websites | |
| 334 websites | |
| 315 websites | |
| 241 websites | |
| 233 websites | |
| 205 websites |
| .org | 5,127 websites |
| .com | 3,024 websites |
| .it | 443 websites |
| .de | 327 websites |
| .net | 216 websites |
| .org.uk | 211 websites |
| .fr | 173 websites |
| .ca | 173 websites |
| .co.uk | 154 websites |
| .nl | 104 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| ****.info | **,*** | ||
| ***********.org | **,*** | ||
| *********.org | **,*** | ||
| ********.org | **,*** | ||
| ************.org | **,*** | ||
| **************.com | **,*** | ||
| ******.info | **,*** | ||
| ****************.com | ***,*** | ||
| **************.***.uk | ***,*** | ||
| *****.org | ***,*** |
FAQ