The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the give_update_payment_status() function in all versions up to, and including, 4.5.0. This makes it possible for authenticated attackers, with GiveWP Worker-level access and above, to update donations statuses. This ability is not present in the user interface.
We have discovered 10,733 live websites that are affected by CVE-2025-7221.
| Product | |
| Category | Wordpress Plugins |
| Vulnerable Domains | 10,733 live websites (33% of GiveWP install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 226 versions ( 93% of all versions) |
| 4,620 websites | |
| 841 websites | |
| 673 websites | |
| 616 websites | |
| 535 websites | |
| 293 websites | |
| 275 websites | |
| 214 websites | |
| 191 websites | |
| 176 websites |
| .org | 4,330 websites |
| .com | 2,591 websites |
| .it | 399 websites |
| .de | 298 websites |
| .net | 191 websites |
| .org.uk | 175 websites |
| .fr | 166 websites |
| .ca | 151 websites |
| .co.uk | 131 websites |
| .nl | 89 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| ****.info | **,*** | ||
| *********.org | **,*** | ||
| ********.org | **,*** | ||
| ************.org | **,*** | ||
| **************.com | **,*** | ||
| ******.info | **,*** | ||
| **************.***.uk | ***,*** | ||
| *****.org | ***,*** | ||
| **********.org | ***,*** | ||
| ****************.org | ***,*** |
FAQ