CVE-2025-8620
WordPress vulnerability analysis and mitigation

Overview

CVE-2025-8620 affects the GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress in versions up to and including 4.6.0. The vulnerability was discovered and disclosed in August 2025, with the initial CVE record being published on August 6, 2025. This security issue allows unauthenticated attackers to extract sensitive donor information including names, emails, and donor IDs (NVD).

Technical details

The vulnerability is classified as an Information Exposure issue (CWE-200) that exposes sensitive donor information directly in the website's source code. The vulnerability exists within the GiveDonationOptions JavaScript object where donor information is inadvertently exposed. The CVSS v3.1 base score is 5.3 (Medium), with the vector string CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N, indicating that the vulnerability can be exploited remotely without requiring privileges or user interaction (Wordfence).

Impact

The vulnerability exposes donor names, email addresses, and donor IDs to potential attackers. However, it's important to note that payment information, billing details, passwords, credentials, and administrative data were not exposed in this vulnerability (LinkedIn).

Mitigation and workarounds

The vulnerability has been patched in version 4.6.1 of the GiveWP plugin. Site administrators are strongly advised to update their GiveWP plugin immediately to this version to restore full donor privacy protections. The update can be performed through the WordPress Dashboard by navigating to Plugins > Installed Plugins and updating GiveWP to the latest version (LinkedIn).

Community reactions

The vulnerability was initially reported through GitHub issues, where security researchers highlighted the exposure of donor information. GiveWP responded promptly by releasing a critical privacy fix and actively communicating with users through various channels including LinkedIn about the importance of updating to the patched version (GitHub, LinkedIn).

Additional resources


SourceThis report was generated using AI

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management