Pi-hole Donor Data Breach Exposes Email Security Flaw

Pi-hole disclosed a security breach where donor emails were exposed due to a WordPress plugin vulnerability. No financial data was compromised, but the team criticized the plugin developer's response timeline.

Pi-hole Donor Data Breach Exposes Email Security Flaw
Facebook X LinkedIn Bluesky WhatsApp
de flag en flag es flag fr flag nl flag pt flag

Pi-hole Discloses Donor Email Security Incident

Pi-hole has revealed a security breach that exposed donor email addresses through a vulnerability in their WordPress donation system. The open-source DNS filtering project confirmed that names and email addresses provided during donations were publicly accessible in webpage source code.

What Information Was Compromised

The breach affected only names and email addresses submitted through Pi-hole's donation form. Financial information remained secure as payment processing is handled externally by Stripe and PayPal. The Pi-hole product itself remains unaffected by this incident.

Timeline of Discovery

On July 28, 2025, Pi-hole began receiving reports from donors about suspicious emails. The team traced the issue to their donation page plugin after users reported seeing donor information exposed through simple 'view page source' actions. Reddit posts and Discourse forum discussions helped identify the problem.

Plugin Vulnerability Identified

The security flaw existed in GiveWP, a WordPress donation plugin. Version 4.6.1 contained a critical patch addressing 'donor information visibility.' An archived GitHub issue shows the vulnerability allowed public access to donor data through page source inspection.

Response and Responsibility

Pi-hole expressed disappointment in GiveWP's handling of the security fix and communication timeline. While the patch was released within hours of the report, official notification was delayed. Pi-hole has taken full responsibility for the incident and apologized to affected donors, emphasizing their commitment to rebuilding trust.

Related

Orange Implements New Security Measures After Major Data Breach
Crime
AI relevance 94.4%

Orange Implements New Security Measures After Major Data Breach

Orange Belgium introduces SMS notifications for SIM-swap requests after 850,000 customer records were stolen,...

Plex Media Platform Suffers Data Breach, Forces Password Resets
Technology
AI relevance 88.9%

Plex Media Platform Suffers Data Breach, Forces Password Resets

Plex media streaming platform suffers data breach compromising user emails, usernames and hashed passwords. Second...

Rituals Data Breach Explained: Hack Matches Odido Scale | Cybersecurity Guide
Technology
AI relevance 77.8%

Rituals Data Breach Explained: Hack Matches Odido Scale | Cybersecurity Guide

Rituals cosmetics confirms major data breach affecting millions of customer records across 33 countries in April...

Odido Data Breach 2026: 6.2 Million Accounts Exposed in Netherlands' Largest Hack
Crime
AI relevance 72.2%

Odido Data Breach 2026: 6.2 Million Accounts Exposed in Netherlands' Largest Hack

Odido's 2026 data breach exposed 6.2 million customer accounts in Netherlands' largest hack, with stolen data...

Orange Belgium Cyberattack Exposes 850,000 Customer Accounts
Crime
AI relevance 66.7%

Orange Belgium Cyberattack Exposes 850,000 Customer Accounts

Orange Belgium suffered a cyberattack compromising 850,000 customer accounts, exposing personal data but protecting...