The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘name’ parameter in all versions up to, and including, 4.13.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Avatars must be enabled in the WordPress install in order to exploit the vulnerability.
We have discovered 14,482 live websites that are affected by CVE-2025-13206.
| Product | |
| Category | Wordpress Plugins |
| Vulnerable Domains | 14,482 live websites (45% of GiveWP install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 238 versions ( 98% of all versions) |
| 6,677 websites | |
| 1,037 websites | |
| 895 websites | |
| 747 websites | |
| 650 websites | |
| 380 websites | |
| 368 websites | |
| 274 websites | |
| 272 websites | |
| 243 websites |
| .org | 6,009 websites |
| .com | 3,539 websites |
| .it | 496 websites |
| .de | 365 websites |
| .net | 250 websites |
| .org.uk | 246 websites |
| .ca | 206 websites |
| .fr | 198 websites |
| .co.uk | 177 websites |
| .nl | 127 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| ****.info | **,*** | ||
| ***********.org | **,*** | ||
| ****.org | **,*** | ||
| *********.org | **,*** | ||
| ********.org | **,*** | ||
| ************.org | **,*** | ||
| **************.com | **,*** | ||
| ******.info | **,*** | ||
| ****************.com | ***,*** | ||
| **************.***.uk | ***,*** |
FAQ