Give
Recent Updates
Security
- Hardened donor-account email access authentication.
- Improved validation of the checkout login form.
Fixes
- Resolved an issue where paused or failing Stripe Payment Element subscriptions remained stuck when the donor updated their payment method or the subscription was resumed in Stripe.
- Resolved a conflict where scripts enqueued by other plugins while a donation form was being rendered could stop the form builder design preview and embedded forms from loading.
- Resolved an issue where editing a page could exhaust the PHP call stack when a theme or plugin filtered post metadata.
- Activation banner for addons doesn't show when addons are activated from the Unified License Manager
Fixes
- Resolved an issue where recurring donations paid with Square failed when the donor's card or bank required additional verification
- Resolved an issue where paused or failing Stripe subscriptions were not reactivated when resumed in Stripe
Fixes
- Resolved an issue where subscription renewals were assigned the default fund instead of the fund set on their subscription.
Security
- Added additional validation to PayPal Standard IPN.
Tweaks
- Improved the unified licensing page experience.
Security
- Added additional validation when handling serialized data during the donation process.
- Added additional escaping and validation to legacy donor admin screens and the donors REST API.
- Strengthened validation of the donor email-access token and the donation receipt email preview.
- Added a capability check to the onboarding form preview screen to prevent unauthorized access.
- Added nonce verification to the front-end registration handler and restricted automatic donor account linking to the verified donation checkout flow.
Fixes
- Added validation to prevent empty password updates in the Donor Dashboard.
- Resolved an issue where uploading a ZIP add-on with a folder name that differs from the ZIP filename (e.g. give-recurring-donations-2.19.0.zip containing the folder give-recurring/) would fail to detect the plugin after extraction.
Security
- Strengthened security on legacy donors listing and donation details pages.
Fixes
- Resolved an issue where selecting a donation amount level would also select other levels with the same value.
- Resolved an issue where extra separators could render in the donation confirmation page header when line breaks were present in the header text.
- Resolved an issue where refunding a donation made with a per-form Stripe account would fail because the refund request used the default account instead of the form-specific account.
Fixes
- Resolved an issue where the
{team_name}email tag did not display the team name in the "New Fundraiser Joined - No Approval Needed" admin email - Resolved an issue where deleting a P2P team prompted admins to decide whether Team Members should be deleted, but provided no option to make that choice
Security
- Added additional validation to the core settings importer.
- Added additional escaping to donor information displayed in the admin.
- Added additional escaping to the Sequoia (Multi-Step Form) template output. (CVE-2026-14987)
Security
- Added additional validation to ensure donation gateway selection respects the enabled payment gateway settings.
- Improved escaping of donation form template output.
- Improved the security of the recurring donation REST API.