# GiveWP – Donation Plugin and Fundraising Platform <= 4.18.0 - Unauthenticated Insufficient Verification of Data Authenticity via PayPal Standard IPN Notifications

- **ID:** WPSEC-2026-0598
- **Plugin:** GiveWP – Donation Plugin and Fundraising Platform (`give`), https://wordpress.org/plugins/give/
- **Affected versions:** all versions before 4.18.0.1
- **Fixed in:** 4.18.0.1 (Update to 4.18.0.1 or later.)
- **Severity:** Low 3.7 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N)
- **Weakness:** CWE-345
- **Usage among sites WPSec scans:** plugin Medium, affected versions Medium (as of 2026-10-07)
- **Attack surface analysis:** https://attacksurface.wpsec.com/plugin/give
- **Fix released:** 2026-10-06
- **Published:** 2026-10-07
- **URL:** https://wpsec.com/vuln/WPSEC-2026-0598/

## Description

The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Insufficient Verification of Data Authenticity via the PayPal Standard IPN listener in all versions up to, and including, 4.18.0. This is due to the plugin validating IPN notifications with PayPal over a connection that does not verify PayPal's TLS certificate, and to checks on the notification data that fail open: notifications are accepted when the IPN receiver_email and business fields are missing, refund notifications are accepted without a parent transaction ID or a valid refund amount, and a transaction ID already recorded on another donation is not rejected. This makes it possible for unauthenticated attackers who can intercept or spoof the site's server-side connection to PayPal to submit forged IPN notifications that mark PayPal Standard donations as completed without payment, or mark completed donations as refunded.

## References

- https://wpsec.com/vuln/WPSEC-2026-0598/
- https://plugins.svn.wordpress.org/give/tags/4.18.0.1/
- https://wordpress.org/plugins/give/

Source: WPSec, https://wpsec.com/vuln/WPSEC-2026-0598/

License: CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/). Free to use, share and adapt, also commercially, if you credit WPSec and link to this advisory.
