The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `registerAssociateFormsWithCampaign` function in all versions up to, and including, 4.10.0. This makes it possible for unauthenticated attackers to associate any donation forms with any campaign.
We have discovered 12,458 live websites that are affected by CVE-2025-11228.
| Product | |
| Category | Wordpress Plugins |
| Vulnerable Domains | 12,458 live websites (39% of GiveWP install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 234 versions ( 96% of all versions) |
| 5,569 websites | |
| 938 websites | |
| 779 websites | |
| 673 websites | |
| 586 websites | |
| 334 websites | |
| 315 websites | |
| 241 websites | |
| 233 websites | |
| 205 websites |
| .org | 5,127 websites |
| .com | 3,024 websites |
| .it | 443 websites |
| .de | 327 websites |
| .net | 216 websites |
| .org.uk | 211 websites |
| .fr | 173 websites |
| .ca | 173 websites |
| .co.uk | 154 websites |
| .nl | 104 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| ****.info | **,*** | ||
| ***********.org | **,*** | ||
| *********.org | **,*** | ||
| ********.org | **,*** | ||
| ************.org | **,*** | ||
| **************.com | **,*** | ||
| ******.info | **,*** | ||
| ****************.com | ***,*** | ||
| **************.***.uk | ***,*** | ||
| *****.org | ***,*** |
FAQ