GiveWP – Donation Plugin and Fundraising Platform <= 4.10.0 - Missing Authorization to Unauthenticated Forms and Campaigns Disclosure

2025-10-03 14:14
Rafshanzani Suhada

Strategic Overview

Status
Patched in 4.10.1
Affected Version<= 4.10.0
CVSS6.5Medium
CVECVE-2025-11227
View all GiveWP – Donation Plugin and Fundraising Platform vulnerabilities

Vulnerability Overview

The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 4.10.0 via the 'registerGetForm', 'registerGetForms', 'registerGetCampaign' and 'registerGetCampaigns' functions due to a missing capability check. This makes it possible for unauthenticated attackers to extract data from private and draft donation forms, as well as archived campaigns.

Technical Analysis

REMEDIATION: Update to version 4.10.1, or a newer patched version --- IDENTIFIER: CWE-285 (Improper Authorization) The product does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C