Known vulnerabilities in the Givewp plugin
52 security advisories have been published for the Givewp plugin. Each entry below states what an attacker can do, what privilege they need, and the version the issue was fixed in.
- GiveWP - Cross-Site Scripting (XSS) (CVE-2026-5510) MEDIUM
- GiveWP - Broken Access Control (CVE-2026-73352) MEDIUM
- GiveWP - Cross-Site Scripting (XSS) (CVE-2026-66690) HIGH
- Givewp - Security Vulnerability (CVE-2026-14319) HIGH
- Givewp - Security Vulnerability (CVE-2026-14317) MEDIUM
- Givewp - Cross-Site Scripting (XSS) (CVE-2026-14318) MEDIUM
- GiveWP - Cross-Site Scripting (XSS) (CVE-2026-65441) HIGH
- GiveWP - Cross-Site Request Forgery (CSRF) (CVE-2026-65464) MEDIUM
- GiveWP - Cross-Site Scripting (XSS) (CVE-2026-14987) MEDIUM
- GiveWP - Cross-Site Scripting (XSS) (CVE-2026-13704) MEDIUM
- GiveWP - Cross-Site Scripting (XSS) (CVE-2026-13246) MEDIUM
- Givewp - Cross-Site Request Forgery (CSRF) (CVE-2026-11981) MEDIUM
- GiveWP - Cross-Site Scripting (XSS) (CVE-2026-34900) HIGH
- Givewp - Cross-Site Scripting (XSS) (CVE-2025-13206) HIGH
- Givewp - Broken Access Control (CVE-2025-11228) MEDIUM
- Givewp - Information Disclosure (CVE-2025-11227) MEDIUM
- Givewp - Broken Access Control (CVE-2025-7221) MEDIUM
- Givewp - Information Disclosure (CVE-2025-8620) MEDIUM
- Givewp - Cross-Site Scripting (XSS) (CVE-2025-7205) MEDIUM
- Givewp - Security Vulnerability (CVE-2025-4571) MEDIUM
- Givewp - Information Disclosure (CVE-2025-2331) MEDIUM
- Givewp - Information Disclosure (CVE-2025-2025) MEDIUM
- Givewp - Remote Code Execution (CVE-2025-0912) CRITICAL
- Givewp - Remote Code Execution (CVE-2024-12877) CRITICAL
- Givewp - Cross-Site Scripting (XSS) (CVE-2024-11921) MEDIUM
- Givewp - Remote Code Execution (CVE-2024-9634) CRITICAL
- Givewp - Remote Code Execution (CVE-2024-8353) CRITICAL
- Givewp - SQL Injection (CVE-2024-9130) HIGH
- Givewp - Security Vulnerability (CVE-2024-6551) MEDIUM
- Givewp - Broken Access Control (CVE-2024-5941) MEDIUM