CVE-2025-8620
WordPress vulnerability analysis and mitigation

Overview

The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress (CVE-2025-8620) contains an Information Exposure vulnerability affecting all versions up to and including 4.6.0. The vulnerability was discovered and disclosed on August 5, 2025. This security issue affects WordPress installations using the GiveWP plugin, a popular donation and fundraising platform (NVD).

Technical details

The vulnerability allows unauthenticated attackers to extract sensitive donor information including names, emails, and donor IDs directly from the page source code. The issue has been assigned a CVSS v3.1 base score of 5.3 (Medium) with the vector string CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N. The vulnerability is classified as CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor) (NVD, Rapid7).

Impact

The vulnerability exposes donor personal information including names, email addresses, and donor IDs to unauthorized users. However, it's important to note that payment information, billing details, passwords, credentials, and administrative data were not exposed in this vulnerability (LinkedIn Post).

Mitigation and workarounds

The vulnerability has been patched in version 4.6.1 of the GiveWP plugin. Site administrators are strongly advised to update their GiveWP plugin immediately to this version to restore full donor privacy protections. The update can be performed through the WordPress Dashboard under Plugins > Installed Plugins. It is recommended to backup the site before performing the update (LinkedIn Post).

Community reactions

GiveWP responded promptly to the vulnerability disclosure by releasing a critical privacy fix in version 4.6.1. The company has been transparent about the issue, clearly communicating what information was and wasn't exposed, and providing detailed update instructions to their users (LinkedIn Post).

Additional resources


SourceThis report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-47552CRITICAL9.8
  • dzs-videogallery
NoNoJan 07, 2026
CVE-2025-46494HIGH7.1
  • widgetkit-pro
NoNoJan 07, 2026
CVE-2025-46434MEDIUM6.5
  • theplus_elementor_addon
NoYesJan 07, 2026
CVE-2025-14275MEDIUM6.4
  • jeg-elementor-kit
NoYesJan 08, 2026
CVE-2025-12640MEDIUM4.3
  • folders
NoYesJan 08, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management