Cross-Site Request Forgery Vulnerability in StellarWP GiveWP Plugin
CVE-2025-67467

4.5MEDIUM

Key Information:

Vendor

WordPress

Status
Vendor
CVE Published:
9 December 2025

What is CVE-2025-67467?

A Cross-Site Request Forgery (CSRF) vulnerability exists in the StellarWP GiveWP plugin, which could allow an attacker to perform unauthorized actions on behalf of users without their consent. This issue affects all versions from n/a up to and including 4.13.1, posing a significant risk to user data and web application integrity. Website administrators are encouraged to implement the latest security updates to mitigate this risk.

Affected Version(s)

GiveWP <= n/a

References

CVSS V3.1

Score:
4.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

mcdruid | Patchstack Bug Bounty Program
.