The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 4.6.0. This makes it possible for unauthenticated attackers to extract donor names, emails, and donor id.
Metrics
Affected Vendors & Products
References
History
Thu, 07 Aug 2025 07:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Givew
Givew donation Plugin And Fundraising Platform Wordpress Wordpress wordpress |
|
Vendors & Products |
Givew
Givew donation Plugin And Fundraising Platform Wordpress Wordpress wordpress |
Wed, 06 Aug 2025 20:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Wed, 06 Aug 2025 09:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 4.6.0. This makes it possible for unauthenticated attackers to extract donor names, emails, and donor id. | |
Title | GiveWP – Donation Plugin and Fundraising Platform <= 4.6.0 - Unauthenticated Donor Data Exposure | |
Weaknesses | CWE-200 | |
References |
|
|
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: Wordfence
Published: 2025-08-06T09:22:32.841Z
Updated: 2025-08-06T19:29:56.568Z
Reserved: 2025-08-05T20:29:49.881Z
Link: CVE-2025-8620

Updated: 2025-08-06T19:29:52.023Z

Status : Awaiting Analysis
Published: 2025-08-06T10:15:35.967
Modified: 2025-08-06T20:23:37.600
Link: CVE-2025-8620

No data.