CVE-2025-13206

GiveWP - Donation Plugin and Fundraising Platform <= 4.13.0 - Unauthenticated Stored Cross-Site Scripting via 'name'

The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘name’ parameter in all versions up to, and including, 4.13.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Avatars must be enabled in the WordPress install in order to exploit the vulnerability.


We have discovered 14,482 live websites that are affected by CVE-2025-13206.

Run a Free Instant Scan




Affected Software

Product  GiveWP
Category Wordpress Plugins
Vulnerable Domains14,482 live websites (45% of GiveWP install base)
Vulnerable Versions
  • from 0 through 4.13
Vulnerable Versions Count238 versions ( 98% of all versions)


Common Weakness Enumeration

CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')



Details

  • Published - Nov 19, 2025
  • Updated - Nov 19, 2025

Credits

  • Angus Girvan (finder)

Website Distribution by Country

Number of websites using CVE-2025-13206
United States6,677 websites



Germany1,037 websites
GB895 websites
Italy747 websites
France650 websites
Canada380 websites
India368 websites
Australia274 websites
Spain272 websites
Cyprus243 websites

Website Distribution by TLD

Number of websites using CVE-2025-13206
.org6,009 websites
.com3,539 websites
.it496 websites
.de365 websites
.net250 websites
.org.uk246 websites
.ca206 websites
.fr198 websites
.co.uk177 websites
.nl127 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2025-13206

Top websites that are affected by CVE-2025-13206. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
****.info United States**,***
***********.org United States**,***
****.org United States**,***
*********.org GB**,***
********.org United States**,***
************.org United States**,***
**************.com Australia**,***
******.info Italy**,***
****************.com United States***,***
**************.***.uk GB***,***
See full domain list

FAQ

CVE-2025-13206 is Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GiveWP
A total of 14,482 websites have been identified as vulnerable to CVE-2025-13206, based on global website indexing conducted by WebTechSurvey.
The GiveWP is affected by the CVE-2025-13206 vulnerability.
GiveWP versions up to and including 4.13 are vulnerable to CVE-2025-13206.