7.5
CVSSv3

CVE-2025-2025

CVSSv4: NA | CVSSv3: 7.5 | CVSSv2: NA | VMScore: 850 | EPSS: 0.00054 | KEV: Not Included
Published: 15/03/2025 Updated: 25/03/2025

Vulnerability Summary

GiveWP WordPress Plugin Unauthenticated Earnings Report Information Disclosure

The GiveWP – Donation Plugin and Fundraising Platform for WordPress contains a security vulnerability in the give_reports_earnings() function across all versions up to and including 3.22.0. The issue stems from a lack of proper capability verification, which enables unauthenticated attackers to access and disclose sensitive earnings report information without requiring any valid user credentials.

Vulnerable Product Search on Vulmon Subscribe to Product

givewp givewp – donation plugin and fundraising platform

givewp givewp