References https://nvd.nist.gov/vuln/detail/CVE-2025-4571 https://hackhalt.com/threat/cve-2025-4571/ https://cve.imfht.com/detail/CVE-2025-4571?lang=en https://github.com/advisories/GHSA-cpf6-v59q-684c https://wpscan.com/vulnerability/f819ea85-bf28-4e8c-b72b-59741e7e9cee/ https://vuldb.com/vuln/313241 https://cve.imfht.com/detail/CVE-2025-4571 https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/give/givewp-donation-plugin-and-fundraising-platform-4100-missing-authorization-to-unauthenticated-forms-and-campaigns-disclosure
Related VulnerabilitiesPoCCVE-2026-82222: GiveWP <= 4.16.7.1 - Remote Code ExecutionPoCCVE-2021-24213: GiveWP <= 2.9.7 - Cross-Site ScriptingPoCCVE-2020-20627: GiveWP - Missing Authorization to Settings UpdatePoCCVE-2021-25099: WordPress GiveWP <2.17.3 - Cross-Site ScriptingPoCCVE-2024-5932: GiveWP - PHP Object InjectionPoCCVE-2024-8353: GiveWP Donation Plugin <= 3.16.1 - Unauthenticated PHP Object InjectionWordPress GiveWP 插件 /admin-ajax.php 命令执行漏洞(CVE-2024-8353)