The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to unauthorized view and modification of data due to an insufficient capability check on the permissionsCheck functions in all versions up to, and including, 4.3.0. This makes it possible for authenticated attackers, with Contributor-level access and above, to view or delete fundraising campaigns, view donors' data, modify campaign events, etc.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-18683 | The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to unauthorized view and modification of data due to an insufficient capability check on the permissionsCheck functions in all versions up to, and including, 4.3.0. This makes it possible for authenticated attackers, with Contributor-level access and above, to view or delete fundraising campaigns, view donors' data, modify campaign events, etc. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Thu, 10 Jul 2025 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Givewp
Givewp givewp |
|
| CPEs | cpe:2.3:a:givewp:givewp:*:*:*:*:*:wordpress:*:* | |
| Vendors & Products |
Givewp
Givewp givewp |
Fri, 20 Jun 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 19 Jun 2025 07:00:00 +0000
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2025-06-20T13:11:45.801Z
Reserved: 2025-05-12T09:07:33.465Z
Link: CVE-2025-4571
Updated: 2025-06-20T12:38:16.726Z
Status : Analyzed
Published: 2025-06-19T07:15:27.383
Modified: 2025-07-10T00:04:02.257
Link: CVE-2025-4571
No data.
OpenCVE Enrichment
No data.
EUVD