What the vulnerability does
01Description
The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to unauthorized view and modification of data due to an insufficient capability check on the permissionsCheck functions in all versions up to, and including, 4.3.0. This makes it possible for authenticated attackers, with Contributor-level access and above, to view or delete fundraising campaigns, view donors' data, modify campaign events, etc.
Explanation of Vulnerability in Simple Terms
02Summary
GiveWP versions up to 4.3.0 lack proper authorization checks, allowing authenticated users with low privileges to read and modify sensitive donation data they should not access. An attacker with a standard user account can view or alter donation records and related information. Update to a version newer than 4.3.0 to restore proper access controls.
What an attacker can do
03Attacker Capabilities
Read and modify donation records and sensitive data belonging to other users or the organization.
Potential impact on your site
04Site Impact
Donors' personal and financial information may be exposed or altered by unauthorized users with basic site access.
Conditions required to exploit
05Prerequisites
Attacker must have a low-privilege authenticated account on the site (e.g., subscriber or donor account).
Key dates
06Disclosure timeline
June 19, 2025
CVE published
April 8, 2026
Record updated