The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to unauthorized view and modification of data due to an insufficient capability check on the permissionsCheck functions in all versions up to, and including, 4.3.0. This makes it possible for authenticated attackers, with Contributor-level access and above, to view or delete fundraising campaigns, view donors' data, modify campaign events, etc.
We have discovered 10,009 live websites that are affected by CVE-2025-4571.
| Product | |
| Category | Wordpress Plugins |
| Vulnerable Domains | 10,009 live websites (31% of GiveWP install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 222 versions ( 91% of all versions) |
| 4,310 websites | |
| 797 websites | |
| 629 websites | |
| 581 websites | |
| 503 websites | |
| 282 websites | |
| 252 websites | |
| 194 websites | |
| 177 websites | |
| 159 websites |
| .org | 4,023 websites |
| .com | 2,432 websites |
| .it | 373 websites |
| .de | 285 websites |
| .net | 174 websites |
| .fr | 160 websites |
| .org.uk | 156 websites |
| .ca | 137 websites |
| .co.uk | 127 websites |
| .nl | 81 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| ****.info | **,*** | ||
| *********.org | **,*** | ||
| ********.org | **,*** | ||
| ************.org | **,*** | ||
| **************.com | **,*** | ||
| **************.***.uk | ***,*** | ||
| *****.org | ***,*** | ||
| ****************.org | ***,*** | ||
| *************.it | ***,*** | ||
| ******.com | ***,*** |
FAQ