GivingPress Lite

GivingPress Lite has one disclosed vulnerability in the WordSec catalog, all reported in 2024; it remains unpatched as of September 2026. Their average CVSS score is 6.4, and the most serious one scores 6.4 out of 10.

The most common weakness is Cross-Site Scripting, behind 1 of the records (100%).

The one issue recorded for GivingPress Lite has no published fix yet, which makes virtual patching the only reliable mitigation. The oldest unresolved one dates back to 2024.

All of these findings were reported by stealthcopter. GivingPress Lite is installed on roughly 900 WordPress sites, so each unpatched flaw has a wide blast radius. The upstream project has not shipped an update in about 7 years, so new fixes are unlikely to arrive on their own.

Strategic Overview

Avg CVSSMedium
6.4/ 10
Patch Coverage0%
Open

1

Fixed

0

Get automatic notifications for all GivingPress Lite vulnerabilities before they are exploited.

Most severe open issueCVSS 6.4CVE-2024-43352

GivingPress Lite <= 1.8.6 - Authenticated (Contributor+) Stored Cross-Site Scripting

Read the full analysis

Vulnerability Records

1 records
GivingPress Lite screenshot
Latestv1.8.6

GivingPress Lite

Organic Themes

Author

Organic Themes

4.7(7)
94/100
Last Updated
2019-04-15 (8y ago)
Active Installs
900+
Downloads
74,587
Requires WP
0+
Requires PHP
0+
Created
2016-05-02 (11y ago)

A WordPress theme for nonprofit organizations, charities, foundations and cause-driven businesses. GivingPress provides professional website solutions for nonprofit organizations. The theme is perfect for churches, scholarships, education, healthcare, scientific reasearch, political, charity, humanitarian, club and association websites. The responsive design features a modern aesthetic with an emphasis on collecting donations and fundraising. Visit the GivingPress site for more information.

Tags
BlogNewsEducationOne columnCustom logoCustom menuSticky postTwo columnsCustom headerRight sidebarTheme optionsThree columnsFooter widgetsFeatured imagesFlexible headerCustom backgroundTranslation readyFull width templateFeatured image header

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C