GiveWP – Donation Plugin and Fundraising Platform <= 4.18.0 - Unauthenticated Insufficient Verification of Data Authenticity via PayPal Standard IPN Notifications
- ID
- WPSEC-2026-0598
- Plugin
- GiveWP – Donation Plugin and Fundraising Platform (give)
- Affected
- all versions before 4.18.0.1
- Remediation
- Update to 4.18.0.1 or later.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
- Weakness
- CWE-345
- Usage
- Plugin Medium · Affected versions Medium among sites WPSec scans, 2026-10-07
- Attack surface
- GiveWP – Donation Plugin and Fundraising Platform on WPSec AttackSurface
- Fix released
- Published
Description
The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Insufficient Verification of Data Authenticity via the PayPal Standard IPN listener in all versions up to, and including, 4.18.0. This is due to the plugin validating IPN notifications with PayPal over a connection that does not verify PayPal's TLS certificate, and to checks on the notification data that fail open: notifications are accepted when the IPN receiver_email and business fields are missing, refund notifications are accepted without a parent transaction ID or a valid refund amount, and a transaction ID already recorded on another donation is not rejected. This makes it possible for unauthenticated attackers who can intercept or spoof the site's server-side connection to PayPal to submit forged IPN notifications that mark PayPal Standard donations as completed without payment, or mark completed donations as refunded.
References
- https://wpsec.com/vuln/WPSEC-2026-0598/
- https://plugins.svn.wordpress.org/give/tags/4.18.0.1/
- https://wordpress.org/plugins/give/
Published by WPSec. Provided as is, without warranty. Corrections: contact us.
This advisory as JSON or Markdown · All advisories: JSON, RSS