Give
Recent Updates
Security
- Hardened security around team updates (CVE-2026-82663) and campaign sorting (CVE-2026-82568)
Fixes
- Enhanced security around the eCard recipient data. (CVE-2026-19658)
Fixes
- Fixed a campaign’s default donation form appearing unpublished in the form builder.
- Fixed PHP warnings on the form builder screen when its page is opened without the locale or donation form ID query arguments.
- Resolved a plugin conflict that prevented donor first and last names from being recorded when the Charitable plugin was active alongside GiveWP.
- Resolved an issue where the custom amount minimum and maximum also applied to the donation levels and the set donation amount, so a level below the minimum could not be donated. Forms that leave the minimum empty now fall back to the lowest configured amount, and a minimum or maximum with cents is no longer rounded down.
Security
- Removed vulnerable dead code related to legacy donor relinking. (CVE-2026-82676)
- Enhanced security on donor account access. (CVE-2026-82675)
Tweaks
- Replaced the axios HTTP client with WordPress core’s apiFetch in the donor dashboard, reports, onboarding wizard, and the log and migration list tables, and removed axios from the plugin’s JavaScript dependencies.
Fixes
- Resolved an issue where donations failed when the donor’s card or bank required additional verification
Enhancements
- Updated Razorpay integration to be more secure by always validating on the server first.
Notes
- Recurring donations through Razorpay require Give – Recurring Donations 2.20.0 or later
- Updated the bundled Razorpay PHP SDK to 2.9.3, which raises the minimum PHP version to 7.4
Enhancements
- Updated Razorpay integration to be more secure by always validating on the server first. This will require updating RazorPay to version 3.0.0+
Fixes
- Resolved an issue where Razorpay checkout launched before validating required Billing State field
Fixes
- Resolved deprecation warnings for WordPress 7.0 block editor compatibility.
- Resolved an issue where P2P campaign blocks showed as unsupported when editing a P2P Campaign page.
- Resolved an issue where the “My Team” tab was displayed on the fundraiser page even when team registration was disabled.
Fixes
- Resolved an issue where updating exchange rates could fail with a fatal error and leave the settings page loading indefinitely when the exchange rate service returned no rates
Fixes
- Resolved an issue where a failed Braintree donation triggered a critical error on PHP 8.x instead of notifying the donor.
Security
- Added additional hardening for serialized data handling in the donation flow.