Unauthorized Data Modification in GiveWP Donation Plugin for WordPress
CVE-2025-7221
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 21 August 2025
What is CVE-2025-7221?
The GiveWP Donation Plugin for WordPress suffers from a security flaw that allows improper data modification due to inadequate capability verification on the give_update_payment_status() function. This vulnerability affects all versions up to and including 4.5.0. As a result, authenticated users with Worker-level access can change donation statuses without proper authorization, a capability that is absent from the user interface, creating significant risks for data integrity and security. Protect your site by ensuring your plugin is updated to the latest version.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
GiveWP β Donation Plugin and Fundraising Platform * <= 4.5.0
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved