CVE-2025-7221

Source
https://cve.org/CVERecord?id=CVE-2025-7221
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-7221.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-7221
Published
2025-08-21T06:15:34.143Z
Modified
2025-12-05T12:32:35.432275Z
Severity
  • 4.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N CVSS Calculator
Summary
[none]
Details

The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the giveupdatepayment_status() function in all versions up to, and including, 4.5.0. This makes it possible for authenticated attackers, with GiveWP Worker-level access and above, to update donations statuses. This ability is not present in the user interface.

References

Affected packages

Git / github.com/impress-org/givewp

Affected ranges

Type
GIT
Repo
https://github.com/impress-org/givewp
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Affected versions

0.*
0.9.5
0.9.5.1
1.*
1.0
1.0.0
1.0.1
1.1
1.18.18
1.2
1.2.1
1.3
1.3.0.4
1.3.1
1.3.1.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.4
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.5
1.5.1
1.5.2
1.6
1.6.1
1.6.2
1.6.3
1.6.4
1.7
1.7.1
1.7.2
1.8
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.19
1.8.2
1.8.3
1.8.4
1.8.5
1.8.6
1.8.7
1.8.7.1
1.8.8
1.8.9
2.*
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.3
2.1.4
2.1.5
2.10.0
2.10.0-alpha.1
2.10.0-alpha.2
2.10.0-beta.1
2.10.0-beta.2
2.10.0-beta.3
2.10.0-beta.4
2.10.0-rc.1
2.10.0-rc.2
2.10.1
2.10.2
2.10.3
2.10.4
2.11.0
2.11.1
2.11.2
2.11.2-alpha
2.11.3
2.12.0
2.12.0-alpha.1
2.12.0-alpha.2
2.12.0-alpha.3
2.12.0-beta.1
2.12.1
2.12.2
2.12.3
2.13.0
2.13.1
2.13.2
2.13.3
2.13.4
2.14.0
2.14.0-beta.1
2.15.0
2.16.0
2.16.0-rc.1
2.16.1
2.16.2
2.17.0
2.17.1
2.17.2
2.17.3
2.18.0
2.18.1
2.19.0
2.19.0-alpha
2.19.0-alpha.2
2.19.1
2.19.2
2.19.3
2.19.4
2.19.5
2.19.6
2.19.6-alpha
2.19.7
2.19.8
2.2.0
2.2.1
2.2.2
2.2.4
2.2.5
2.20.0
2.20.0-beta.1
2.20.0-beta.2
2.20.0-rc.1
2.20.1
2.20.2
2.21.0
2.21.1
2.21.2
2.21.3
2.21.4
2.22.0
2.22.1
2.22.2
2.22.3
2.23.0
2.23.1
2.23.2
2.24.0
2.24.1
2.24.2
2.25.0
2.25.1
2.25.2
2.25.3
2.26.0
2.27.0
2.27.1
2.27.2
2.27.3
2.28.0
2.29.0
2.29.1
2.29.2
2.3.0
2.30.0
2.31.0
2.31.1
2.32.0
2.33.0
2.33.1
2.33.2
2.33.3
2.33.4
2.33.5
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.4.6
2.4.7
2.5.0
2.5.1
2.5.10
2.5.11
2.5.12
2.5.13
2.5.2
2.5.3
2.5.4
2.5.5
2.5.7
2.5.8
2.5.9
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.1
2.7.2
2.7.3
2.7.4
2.7.5
2.8.0
2.8.0-alpha.1
2.8.0-alpha.2
2.8.0-beta.1
2.8.0-beta.2
2.8.0-beta.3
2.8.0-rc.1
2.8.1
2.9.0
2.9.0-alpha.1
2.9.0-alpha.2
2.9.0-beta.1
2.9.0-beta.2
2.9.0-beta.3
2.9.0-rc.1
2.9.1
2.9.2
2.9.3
2.9.4
2.9.5
2.9.6
2.9.7
3.*
3.0.0
3.0.0-beta.1
3.0.0-rc.1
3.0.0-rc.2
3.0.0-rc.3
3.0.0-rc.4
3.0.0-rc.5
3.0.0-rc.6
3.0.0-rc.7
3.0.0-rc.8
3.0.0-rc.9
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
3.10.0
3.11.0
3.12.0
3.12.1
3.12.2
3.12.3
3.13.0
3.14.0
3.14.1
3.14.2
3.15.0
3.15.1
3.16.0
3.16.1
3.16.2
3.16.3
3.16.4
3.16.5
3.17.0
3.17.1
3.17.2
3.18.0
3.19.0
3.19.1
3.19.2
3.19.3
3.19.4
3.2.0
3.2.1
3.2.2
3.20.0
3.21.0
3.21.1
3.22.0
3.22.1
3.22.2
3.3.0
3.3.1
3.4.0
3.4.1
3.4.2
3.5.0
3.5.1
3.6.0
3.6.1
3.6.2
3.7.0
3.8.0
3.9.0
4.*
4.0.0
4.1.0
4.1.1
4.2.0
4.2.1
4.3.0
4.3.1
4.3.2
4.4.0
4.5.0
4.6.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-7221.json"