GiveWP – Donation Plugin and Fundraising Platform <= 4.18.0 - Unauthenticated Insufficient Verification of Data Authenticity via PayPal Standard IPN Notifications

Low 3.7 CWE-345Fixed in 4.18.0.1
ID
WPSEC-2026-0598
Plugin
GiveWP – Donation Plugin and Fundraising Platform (give)
Affected
all versions before 4.18.0.1
Remediation
Update to 4.18.0.1 or later.
CVSS 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
Weakness
CWE-345
Usage
Plugin Medium · Affected versions Medium among sites WPSec scans, 2026-10-07
Attack surface
GiveWP – Donation Plugin and Fundraising Platform on WPSec AttackSurface
Fix released
Published

Description

The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Insufficient Verification of Data Authenticity via the PayPal Standard IPN listener in all versions up to, and including, 4.18.0. This is due to the plugin validating IPN notifications with PayPal over a connection that does not verify PayPal's TLS certificate, and to checks on the notification data that fail open: notifications are accepted when the IPN receiver_email and business fields are missing, refund notifications are accepted without a parent transaction ID or a valid refund amount, and a transaction ID already recorded on another donation is not rejected. This makes it possible for unauthenticated attackers who can intercept or spoof the site's server-side connection to PayPal to submit forged IPN notifications that mark PayPal Standard donations as completed without payment, or mark completed donations as refunded.

References

Published by WPSec. Provided as is, without warranty. Corrections: contact us.

This advisory as JSON or Markdown · All advisories: JSON, RSS

License: CC BY 4.0