Impact
The vulnerability allows unauthenticated attackers to read donor names, email addresses and donor identifiers, compromising the confidentiality of personal data. It is classified as an information disclosure weakness (CWE‑200).
Affected Systems
WordPress sites that run the GiveWP – Donation Plugin and Fundraising Platform version 4.6.0 or earlier are impacted. The plugin is distributed by stellarwp and is deployed as a WordPress plugin.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate risk. The EPSS score of <1% suggests a low likelihood of exploitation at this time, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is unauthenticated access through the web interface or exposed API endpoints, enabling any visitor to retrieve sensitive donor information.
OpenCVE Enrichment
EUVD