The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 4.6.0. This makes it possible for unauthenticated attackers to extract donor names, emails, and donor id.
We have discovered 10,823 live websites that are affected by CVE-2025-8620.
| Product | |
| Category | Wordpress Plugins |
| Vulnerable Domains | 10,823 live websites (34% of GiveWP install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 227 versions ( 93% of all versions) |
| 4,661 websites | |
| 845 websites | |
| 684 websites | |
| 619 websites | |
| 540 websites | |
| 294 websites | |
| 276 websites | |
| 215 websites | |
| 194 websites | |
| 178 websites |
| .org | 4,364 websites |
| .com | 2,618 websites |
| .it | 401 websites |
| .de | 301 websites |
| .net | 193 websites |
| .org.uk | 179 websites |
| .fr | 166 websites |
| .ca | 152 websites |
| .co.uk | 134 websites |
| .nl | 89 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| ****.info | **,*** | ||
| *********.org | **,*** | ||
| ********.org | **,*** | ||
| ************.org | **,*** | ||
| **************.com | **,*** | ||
| ******.info | **,*** | ||
| **************.***.uk | ***,*** | ||
| *****.org | ***,*** | ||
| **********.org | ***,*** | ||
| ****************.org | ***,*** |
FAQ