CVE-2025-7205

GiveWP – Donation Plugin and Fundraising Platform <= 4.5.0 - Authenticated (GiveWP worker+) Stored Cross-Site Scripting

The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the donor notes parameter in all versions up to, and including, 4.5.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with GiveWP worker-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Additionally, they need to trick an administrator into visiting the legacy version of the site.


We have discovered 10,733 live websites that are affected by CVE-2025-7205.

Run a Free Instant Scan




Affected Software

Product  GiveWP
Category Wordpress Plugins
Vulnerable Domains10,733 live websites (33% of GiveWP install base)
Vulnerable Versions
  • from 0 through 4.5
Vulnerable Versions Count226 versions ( 93% of all versions)


Common Weakness Enumeration

CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')



Details

  • Published - Jul 31, 2025
  • Updated - Jul 31, 2025

Credits

  • Brian Sans-Souci (finder)

Website Distribution by Country

Number of websites using CVE-2025-7205
United States4,620 websites



Germany841 websites
GB673 websites
Italy616 websites
France535 websites
India293 websites
Canada275 websites
Spain214 websites
Australia191 websites
Cyprus176 websites

Website Distribution by TLD

Number of websites using CVE-2025-7205
.org4,330 websites
.com2,591 websites
.it399 websites
.de298 websites
.net191 websites
.org.uk175 websites
.fr166 websites
.ca151 websites
.co.uk131 websites
.nl89 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2025-7205

Top websites that are affected by CVE-2025-7205. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
****.info United States**,***
*********.org GB**,***
********.org United States**,***
************.org United States**,***
**************.com Australia**,***
******.info Italy**,***
**************.***.uk GB***,***
*****.org United States***,***
**********.org United States***,***
****************.org GB***,***
See full domain list

FAQ

CVE-2025-7205 is Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GiveWP
A total of 10,733 websites have been identified as vulnerable to CVE-2025-7205, based on global website indexing conducted by WebTechSurvey.
The GiveWP is affected by the CVE-2025-7205 vulnerability.
GiveWP versions up to and including 4.5 are vulnerable to CVE-2025-7205.