CVE-2025-8620

GiveWP – Donation Plugin and Fundraising Platform <= 4.6.0 - Unauthenticated Donor Data Exposure

The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 4.6.0. This makes it possible for unauthenticated attackers to extract donor names, emails, and donor id.


We have discovered 10,823 live websites that are affected by CVE-2025-8620.

Run a Free Instant Scan




Affected Software

Product  GiveWP
Category Wordpress Plugins
Vulnerable Domains10,823 live websites (34% of GiveWP install base)
Vulnerable Versions
  • from 0 through 4.6
Vulnerable Versions Count227 versions ( 93% of all versions)


Common Weakness Enumeration

CWE-200 Exposure of Sensitive Information to an Unauthorized Actor



Details

  • Published - Aug 6, 2025
  • Updated - Aug 6, 2025

Website Distribution by Country

Number of websites using CVE-2025-8620
United States4,661 websites



Germany845 websites
GB684 websites
Italy619 websites
France540 websites
India294 websites
Canada276 websites
Spain215 websites
Australia194 websites
Cyprus178 websites

Website Distribution by TLD

Number of websites using CVE-2025-8620
.org4,364 websites
.com2,618 websites
.it401 websites
.de301 websites
.net193 websites
.org.uk179 websites
.fr166 websites
.ca152 websites
.co.uk134 websites
.nl89 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2025-8620

Top websites that are affected by CVE-2025-8620. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
****.info United States**,***
*********.org GB**,***
********.org United States**,***
************.org United States**,***
**************.com Australia**,***
******.info Italy**,***
**************.***.uk GB***,***
*****.org United States***,***
**********.org United States***,***
****************.org GB***,***
See full domain list

FAQ

CVE-2025-8620 is Exposure of Sensitive Information to an Unauthorized Actor in GiveWP
A total of 10,823 websites have been identified as vulnerable to CVE-2025-8620, based on global website indexing conducted by WebTechSurvey.
The GiveWP is affected by the CVE-2025-8620 vulnerability.
GiveWP versions up to and including 4.6 are vulnerable to CVE-2025-8620.