CVE-2025-4571

GiveWP – Donation Plugin and Fundraising Platform <= 4.3.0 - Missing Authorization To Authenticated (Contributor+) Campaign Data View And Modification

The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to unauthorized view and modification of data due to an insufficient capability check on the permissionsCheck functions in all versions up to, and including, 4.3.0. This makes it possible for authenticated attackers, with Contributor-level access and above, to view or delete fundraising campaigns, view donors' data, modify campaign events, etc.


We have discovered 10,009 live websites that are affected by CVE-2025-4571.

Run a Free Instant Scan




Affected Software

Product  GiveWP
Category Wordpress Plugins
Vulnerable Domains10,009 live websites (31% of GiveWP install base)
Vulnerable Versions
  • from 0 through 4.3
Vulnerable Versions Count222 versions ( 91% of all versions)


Common Weakness Enumeration

CWE-862 Missing Authorization



Details

  • Published - Jun 19, 2025
  • Updated - Jun 20, 2025

Credits

  • Brian Sans-Souci (finder)

Website Distribution by Country

Number of websites using CVE-2025-4571
United States4,310 websites



Germany797 websites
GB629 websites
Italy581 websites
France503 websites
India282 websites
Canada252 websites
Spain194 websites
Australia177 websites
Cyprus159 websites

Website Distribution by TLD

Number of websites using CVE-2025-4571
.org4,023 websites
.com2,432 websites
.it373 websites
.de285 websites
.net174 websites
.fr160 websites
.org.uk156 websites
.ca137 websites
.co.uk127 websites
.nl81 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2025-4571

Top websites that are affected by CVE-2025-4571. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
****.info United States**,***
*********.org GB**,***
********.org United States**,***
************.org United States**,***
**************.com Australia**,***
**************.***.uk GB***,***
*****.org United States***,***
****************.org GB***,***
*************.it Italy***,***
******.com United States***,***
See full domain list

FAQ

CVE-2025-4571 is Missing Authorization in GiveWP
A total of 10,009 websites have been identified as vulnerable to CVE-2025-4571, based on global website indexing conducted by WebTechSurvey.
The GiveWP is affected by the CVE-2025-4571 vulnerability.
GiveWP versions up to and including 4.3 are vulnerable to CVE-2025-4571.

References