logo

Pi-hole discloses data breach triggered by WordPress plugin flaw

ID: a45ea16f-f602-5478-b4a5-04e26f995798

STIX ID: report--a45ea16f-f602-5478-b4a5-04e26f995798

Feed Name: Bleeping Computer

Threat Score
50/100

Date Published: 2025-08-01

Date Updated: 2026-07-17

Author: Sergiu Gatlan

...
...

**Executive summary:** Pi-hole disclosed that donor names and email addresses were exposed on its donation page because the GiveWP WordPress donation plugin made donor information available in the page source; GiveWP patched the flaw shortly after disclosure, Have I Been Pwned reported ~30,000 impacted records, and Pi-hole stated no payment/financial data or its product were affected.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.