stellarwp Vulnerabilities and Affected Products
Vulnerabilities associated with GiveWP.
Products
Clear product- GiveWP – Donation Plugin and Fundraising Platform31 vulnerabilities
- Kadence Blocks — Page Builder Toolkit for Gutenberg Editor29 vulnerabilities
- The Events Calendar19 vulnerabilities
- GiveWP10 vulnerabilities
- Membership Plugin – Restrict Content7 vulnerabilities
- Event Tickets and Registration6 vulnerabilities
- LearnDash LMS5 vulnerabilities
- Bookit — Booking & Appointment Calendar3 vulnerabilities
- Event Tickets3 vulnerabilities
- Gutenberg Blocks by Kadence Blocks3 vulnerabilities
- Kadence WooCommerce Email Designer3 vulnerabilities
- WPComplete3 vulnerabilities
- Restrict Content2 vulnerabilities
- Give – Divi Donation Modules1 vulnerability
- Image Widget1 vulnerability
- iThemes Sync1 vulnerability
- LearnDash LMS – Reports1 vulnerability
- Membership Plugin – Kadence Memberships1 vulnerability
- the_events_calendar1 vulnerability
- Virtue1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2026-42642MEDIUM | WordPress GiveWP plugin <= 4.14.5 - Broken Access Control vulnerabilityMissing Authorization vulnerability in StellarWP GiveWP give allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects GiveWP: from n/a through <= 4.14.5. CWE-862Apr 29, 2026 | CVSS5.3v3.1 | EPSS0.191% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-67467MEDIUM | WordPress GiveWP plugin <= 4.13.1 - Cross Site Request Forgery (CSRF) vulnerabilityCross-Site Request Forgery (CSRF) vulnerability in StellarWP GiveWP give allows Cross Site Request Forgery.This issue affects GiveWP: from n/a through <= 4.13.1. CWE-352Dec 9, 2025 | CVSS5.4v3.1 | EPSS0.125% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-66533MEDIUM | WordPress GiveWP plugin <= 4.13.1 - Arbitrary Shortocde Execution vulnerabilityImproper Control of Generation of Code ('Code Injection') vulnerability in StellarWP GiveWP give allows Code Injection.This issue affects GiveWP: from n/a through <= 4.13.1. CWE-94Dec 9, 2025 | CVSS6.5v3.1 | EPSS0.271% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-22777CRITICAL | WordPress GiveWP Plugin <= 3.19.3 - PHP Object Injection vulnerabilityDeserialization of Untrusted Data vulnerability in StellarWP GiveWP give allows Object Injection.This issue affects GiveWP: from n/a through <= 3.19.3. CWE-502Jan 13, 2025 | CVSS9.8v3.1 | EPSS0.936% | PoCs2 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-12877CRITICAL | GiveWP – Donation Plugin and Fundraising Platform <= 3.19.2 - Unauthenticated PHP Object InjectionThe GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.19.2 via deserialization of untrusted input from the donation form like 'firstName'. This makes it possible for unauthenticated attackers to inject a PHP Object. The additional presence of a POP chain allows attackers to delete arbitrary files on the server that makes remote code execution possible. Please note this was only partially patched in… CWE-502Jan 11, 2025 | CVSS9.8v3.1 | EPSS1.26% | PoCs2 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-47183MEDIUM | WordPress GiveWP plugin <= 2.33.1 - Broken Access Control vulnerabilityMissing Authorization vulnerability in StellarWP GiveWP give allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects GiveWP: from n/a through <= 2.33.1. CWE-862Jan 2, 2025 | CVSS5.3v3.1 | EPSS0.419% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-47315MEDIUM | WordPress GiveWP – Donation Plugin and Fundraising Platform plugin <= 3.15.1 - Cross Site Request Forgery (CSRF) vulnerabilityCross-Site Request Forgery (CSRF) vulnerability in StellarWP GiveWP give.This issue affects GiveWP: from n/a through <= 3.15.1. CWE-352Sep 25, 2024 | CVSS5.4v3.1 | EPSS0.212% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-35679HIGH | WordPress GiveWP plugin <= 3.12.0 - Reflected Cross Site Scripting (XSS) vulnerabilityImproper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in StellarWP GiveWP give.This issue affects GiveWP: from n/a through <= 3.12.0. CWE-79Jun 8, 2024 | CVSS7.1v3.1 | EPSS0.33% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-30229HIGH | WordPress Give plugin <= 3.4.2 - PHP Object Injection vulnerabilityDeserialization of Untrusted Data vulnerability in StellarWP GiveWP give.This issue affects GiveWP: from n/a through <= 3.4.2. CWE-502Mar 28, 2024 | CVSS8.0v3.1 | EPSS0.622% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-27987HIGH | WordPress Give plugin <= 3.3.1 - Reflected Cross Site Scripting (XSS) vulnerabilityImproper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in StellarWP GiveWP give.This issue affects GiveWP: from n/a through <= 3.3.1. CWE-79Mar 15, 2024 | CVSS7.1v3.1 | EPSS0.354% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |