Vulnerability in GiveWP – Donation Plugin and Fundraising Platform — CVE-2026-85113
MediumSeverity
0.2%Estimated exploit probability
100,000+ sitesInstalls
4.16.9Fixed in
What to do now
Update GiveWP – Donation Plugin and Fundraising Platform to 4.16.9 or later.
Affected versions
- 4.13.2 up to (but not including) 4.16.9
Affected: GiveWP – Donation Plugin and Fundraising Platform (plugin, give)
What the vulnerability is
The GiveWP WordPress plugin before 4.16.9 does not remove shortcode delimiters from donor-supplied values before rendering them on public pages, and the shortcode stripping it applies can be defeated by nesting, allowing unauthenticated users to execute arbitrary shortcodes registered on the site.