PT-2025-47446 · WordPress · Givewp – Donation Plugin/Fundraising Platform

Angus Girvan

·

Published

2025-11-19

·

Updated

2025-11-24

·

CVE-2025-13206

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions GiveWP – Donation Plugin and Fundraising Platform versions prior to 4.13.1
Description The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is susceptible to Stored Cross-Site Scripting. This is due to insufficient input sanitization and output escaping in the name parameter. An unauthenticated attacker can inject arbitrary web scripts into pages. These scripts will execute when a user accesses the injected page. Avatars must be enabled in the WordPress installation for exploitation to be successful.
Recommendations Update GiveWP – Donation Plugin and Fundraising Platform to version 4.13.1 or later.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2025-13206

Affected Products

Givewp – Donation Plugin/Fundraising Platform