Skip to content
WP Hack FixEst. 2005

Security news

GiveWP donation plugin: a 10-out-of-10 flaw anyone on the internet could use

Published · Disclosed August 27, 2026 · Reviewed by Adam Taylor

PluginVulnerableFixed in
GiveWP – Donation Plugin and Fundraising Platform<= 4.16.7.14.16.7.2

If you take donations through WordPress, stop and check your plugin version before you read any further. This one is as bad as the scoring system allows.

GiveWP had a flaw scored 10.0 out of 10, the maximum. It was fixed in version 4.16.7.2, released on August 27.

Am I affected?

You’re affected if your site runs GiveWP 4.16.7.1 or earlier. Check the version under Plugins in your dashboard.

Two details make this worse than the usual plugin flaw:

  • No login was needed. The plugin exposed its own sign-up route, which worked even on sites where WordPress registration is turned off. An attacker could create the account they needed.
  • A default setup was enough. On the affected versions, one published donation form and one active payment method were all it took, and both exist on a normal GiveWP site out of the box.

What an attacker could do

Run commands on your server as the website itself. From there: create admin accounts, install backdoors, read the database, or quietly alter pages.

On a donation site, the database is the concerning part. It holds donor names, email addresses, mailing addresses, and donation histories. Card numbers themselves are normally held by your payment processor rather than your site, but everything around them usually isn’t.

What to do

  1. Update GiveWP to 4.16.7.2 or later today.
  2. Check your users list for administrators or subscribers you don’t recognize, especially any created since late August.
  3. Look at recent donations for odd test-sized amounts or entries with nonsense names. Attack attempts often leave traces there.
  4. If you find anything, don’t stop at deleting it. The account is usually the visible part; the file that created it stays behind.
  5. If your site was on an old version for weeks, it’s worth having it checked rather than assuming the update fixed everything. Updating closes the door, but it doesn’t remove anyone already inside.

Were donor records exposed? That’s a question worth taking seriously rather than guessing at. If your site was running a vulnerable version and you see signs of compromise, the answer affects what you owe your donors, and in some states, what you’re legally required to tell them. Talk to us and we’ll help you work out what actually happened.

On a Protect plan? This is covered by the updates we run.

Worried your site's already been hit?

If something looks wrong, we'll check it and clean it up. If we can't fix it, you don't pay.

We reply within 1 business day (Mon–Fri, 9–5 ET)