CVE-2025-11228

GiveWP – Donation Plugin and Fundraising Platform <= 4.10.0 - Missing Authorization to Unauthenticated Forms-Campaign Association

The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `registerAssociateFormsWithCampaign` function in all versions up to, and including, 4.10.0. This makes it possible for unauthenticated attackers to associate any donation forms with any campaign.


We have discovered 12,458 live websites that are affected by CVE-2025-11228.

Run a Free Instant Scan




Affected Software

Product  GiveWP
Category Wordpress Plugins
Vulnerable Domains12,458 live websites (39% of GiveWP install base)
Vulnerable Versions
  • from 0 through 4.10
Vulnerable Versions Count234 versions ( 96% of all versions)


Common Weakness Enumeration

CWE-862 Missing Authorization



Details

  • Published - Oct 4, 2025
  • Updated - Oct 6, 2025

Credits

  • Rafshanzani Suhada (finder)

Website Distribution by Country

Number of websites using CVE-2025-11228
United States5,569 websites



Germany938 websites
GB779 websites
Italy673 websites
France586 websites
India334 websites
Canada315 websites
Spain241 websites
Australia233 websites
Cyprus205 websites

Website Distribution by TLD

Number of websites using CVE-2025-11228
.org5,127 websites
.com3,024 websites
.it443 websites
.de327 websites
.net216 websites
.org.uk211 websites
.fr173 websites
.ca173 websites
.co.uk154 websites
.nl104 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2025-11228

Top websites that are affected by CVE-2025-11228. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
****.info United States**,***
***********.org United States**,***
*********.org GB**,***
********.org United States**,***
************.org United States**,***
**************.com Australia**,***
******.info Italy**,***
****************.com United States***,***
**************.***.uk GB***,***
*****.org United States***,***
See full domain list

FAQ

CVE-2025-11228 is Missing Authorization in GiveWP
A total of 12,458 websites have been identified as vulnerable to CVE-2025-11228, based on global website indexing conducted by WebTechSurvey.
The GiveWP is affected by the CVE-2025-11228 vulnerability.
GiveWP versions up to and including 4.10 are vulnerable to CVE-2025-11228.