CVE-2025-67467

WordPress GiveWP plugin <= 4.13.1 - Cross Site Request Forgery (CSRF) vulnerability

Cross-Site Request Forgery (CSRF) vulnerability in StellarWP GiveWP give allows Cross Site Request Forgery.This issue affects GiveWP: from n/a through <= 4.13.1.


We have discovered 15,690 live websites that are affected by CVE-2025-67467.

Run a Free Instant Scan




Affected Software

Product  GiveWP
Category Wordpress Plugins
Vulnerable Domains15,690 live websites (49% of GiveWP install base)
Vulnerable Versions
  • from 0 through 4.13.1
Vulnerable Versions Count239 versions ( 98% of all versions)



Details

  • Published - Dec 9, 2025
  • Updated - Feb 10, 2026

Credits

  • mcdruid | Patchstack Bug Bounty Program (finder)

Website Distribution by Country

Number of websites using CVE-2025-67467
United States7,342 websites



Germany1,101 websites
GB972 websites
Italy792 websites
France688 websites
Canada413 websites
India399 websites
Australia296 websites
Spain291 websites
Cyprus262 websites

Website Distribution by TLD

Number of websites using CVE-2025-67467
.org6,564 websites
.com3,816 websites
.it526 websites
.de390 websites
.org.uk278 websites
.net276 websites
.ca228 websites
.fr210 websites
.co.uk188 websites
.nl140 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2025-67467

Top websites that are affected by CVE-2025-67467. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
****.info United States**,***
***********.org United States**,***
****.org United States**,***
*********.org GB**,***
********.org United States**,***
************.org United States**,***
**************.com Australia**,***
******.info Italy**,***
****************.com United States***,***
**************.***.uk GB***,***
See full domain list

FAQ

A total of 15,690 websites have been identified as vulnerable to CVE-2025-67467, based on global website indexing conducted by WebTechSurvey.
The GiveWP is affected by the CVE-2025-67467 vulnerability.
GiveWP versions up to and including 4.13.1 are vulnerable to CVE-2025-67467.