WP Vulnerability WatchVulnerability data as of September 23, 2026

Vulnerability alerts / September 21, 2026

Vulnerability in GiveWP – Donation Plugin and Fundraising Platform — CVE-2026-85113

MediumSeverity
CVSS 6.5
0.2%Estimated exploit probability
EPSS
100,000+ sitesInstalls
4.16.9Fixed in

What to do now

Update GiveWP – Donation Plugin and Fundraising Platform to 4.16.9 or later.

Affected versions

  • 4.13.2 up to (but not including) 4.16.9

Affected: GiveWP – Donation Plugin and Fundraising Platform (plugin, give)

Check: The plugin on wordpress.org / Our record for GiveWP – Donation Plugin and Fundraising Platform

What the vulnerability is

The GiveWP WordPress plugin before 4.16.9 does not remove shortcode delimiters from donor-supplied values before rendering them on public pages, and the shortcode stripping it applies can be defeated by nesting, allowing unauthenticated users to execute arbitrary shortcodes registered on the site.

This description is reproduced verbatim from the public vulnerability record.

Sources

This page is compiled automatically from public databases. Accuracy is not guaranteed; confirm against the vendor advisory before acting.

See other alerts