Give
Recent Updates
Security
- Improved validation of PayPal Standard IPN notifications.
Fixes
- Resolved an issue where PayPal Standard donations and subscription renewals with recovered fees were not recorded after the IPN validation update.
Enhancements
- Improved donations list table performance on sites with hundreds of thousands of donations by paging on IDs first, fixing the total count query, and replacing the single-column donation meta indexes with composite ones
- Improved the Reports screen and legacy earnings stats on large sites by summing and counting donations in the database instead of loading every donation into memory
- Improved donation processing speed by skipping unnecessary offline donation email checks
Fixes
- Recurring donation stats on the campaigns list now read from the cache correctly instead of showing empty values
- Campaign stats now show for campaigns that were added after the stats cache was built
- Resolved an issue where campaign stats showed as zero after viewing the Campaigns screen with test mode enabled
- Donations list table was running extremely slowly and including trashed donations on large sites.
- Resolved an issue where a database error while saving a donation, donor, subscription, campaign, or event caused a critical error and hid the real cause
- Resolved an issue where sites running PHP 8.4 or newer logged deprecation notices from GiveWP
- Database migrations started a second time in requests that arrive while a slow migration is still running. Now it runs one time and the migrations list now shows the latest run first.
- Resolved an issue where a PHP warning could appear on development copies of GiveWP that have not been built
- Resolved an issue where subscription webhook events caused a fatal error when the subscription had no initial donation
- Updated campaign duplication to create a single copy of each associated form when form metadata contains duplicate keys.
- Restored donor names, initials, and totals on the donor wall block and shortcode.
Security
- Enhanced security in Stripe webhook module
- Enhanced security on the campaign block. (CVE-2026-97643)
- Enhanced security for the Donor Dashboard access.
Fixes
- Resolved an issue where duplicating a donation form created a duplicate Recurring Donations goal format setting
Features
- Added the ability to embed donation forms on any website with a copy-paste snippet from the form builder
Enhancements
- Donation form embeds now show a loading state while the form loads
Fixes
- Fixed PHP 8.4 deprecation notices about implicitly nullable parameters
- Fixed the revenue table index migration adding duplicate indexes when it runs more than once
- Added additional escaping to the legacy donation form’s billing address fields.
Security
- Donors can no longer add unverified email addresses to their own donor record.
- Enhanced security for donations imported from CSV
Security
- Added additional validation to PayPal Commerce donation processing.
- Added additional sanitization to donor information displayed on public pages.
Fixes
- Resolved an issue where resuming a paused Stripe subscription triggered a fatal error.
Fixes
- Resolved a fatal error when GoCardless account-level webhooks referenced subscriptions that do not exist in GiveWP
Fixes
- Resolved a fatal error when the REST API index was requested in help context.
Fixes
- Resolved a PHP 8 fatal error on the donation details screen when the global Tribute Options have never been saved.
Fixes
- Resolved an issue where donations with the Mailchimp opt-in selected could fail when the audience list contained duplicate or empty entries.
Security
- Improved validation of the event tickets purchase flow.
- Added additional validation to PayPal Commerce completed-order processing.
- Added additional validation to donor email lookups. Thanks Jakub Herman for responsibly disclosing this issue.