CVE-2025-2025
WordPress vulnerability analysis and mitigation

Overview

CVE-2025-2025 is a security vulnerability discovered in the GiveWP WordPress donation plugin that was disclosed on March 7th, 2025. The vulnerability affects versions prior to 3.22.1 and involves a missing permission check in a GiveWP reporting request functionality (GiveWP Changelog).

Technical details

The vulnerability stems from a missing authentication check in the reporting functionality of GiveWP. The issue was specifically related to the reports.php file where a permission verification was required but absent, potentially allowing unauthorized access to reporting features. This was addressed by adding a permission check using the currentusercan() function to verify if users have the 'viewgivereports' capability (WordPress Plugin).

Impact

The vulnerability could allow unauthorized users to access sensitive reporting information within the GiveWP plugin. This could potentially expose donor information, donation history, and other confidential fundraising data that should only be accessible to authorized administrators (GiveWP Changelog).

Mitigation and workarounds

The vulnerability was patched in GiveWP version 3.22.1. Site administrators are strongly advised to update to this version or later to protect their installations. The fix involves the implementation of proper permission checking before allowing access to reporting functionality (GiveWP Changelog).

Additional resources


SourceThis report was generated using AI

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management