Description
The GiveWP WordPress plugin before 4.16.3 does not restrict the set of available payment gateways to those enabled by the administrator, deriving it in part from request input, which allows unauthenticated users to complete donations through a payment gateway the administrator has disabled.
Published: 2026-07-31
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The GiveWP WordPress plugin, when installed in versions earlier than 4.16.3, fails to enforce the administrator‑defined list of active payment gateways. Instead, it derives part of the gateway selection from user input, allowing an unauthenticated user to specify and process a donation using any payment gateway, even those disabled. This flaw can lead to unauthorized monetary transfers, confusion over campaign funding, and potential loss of trust in the site’s donation system.

Affected Systems

Any website running the GiveWP plugin for WordPress prior to version 4.16.3 is vulnerable. Administrators using the default plugin configuration, which typically includes disabling certain gateways, will unknowingly expose the site to this bypass. No additional vendor or product details are available; the issue is tied solely to the GiveWP plugin itself.

Risk and Exploitability

The exploit does not require privileged access or prior knowledge of credentials; it simply involves crafting a request to the donation completion endpoint with a gateway value that the site has disabled. Because the vulnerability is tied to user input, it can be triggered by anyone who can submit donation forms. While the CVSS score is 5.3, the ability to conduct unauthorized financial transactions renders the threat significant. The EPSS score is < 1%, and there is no indication of exploitation in public feeds (KEV status lists it as not in the catalog). Nonetheless, the straightforward attack vector and potential impact warrant prompt remediation.

Generated by OpenCVE AI on August 4, 2026 at 11:32 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the GiveWP plugin to version 4.16.3 or later to restore proper gateway restrictions
  • Adjust the plugin’s gateway configuration to ensure that any disabled gateways are truly blocked in the settings
  • As an interim safeguard, block unauthenticated POST requests to the donation completion endpoint using a web application firewall or a security plugin that enforces authentication for sensitive actions

Generated by OpenCVE AI on August 4, 2026 at 11:32 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 03 Aug 2026 10:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
CWE-285

Fri, 31 Jul 2026 19:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
CWE-285

Fri, 31 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-862
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 31 Jul 2026 07:45:00 +0000

Type Values Removed Values Added
First Time appeared Givewp
Givewp givewp
Wordpress
Wordpress wordpress
Vendors & Products Givewp
Givewp givewp
Wordpress
Wordpress wordpress

Fri, 31 Jul 2026 06:30:00 +0000

Type Values Removed Values Added
Description The GiveWP WordPress plugin before 4.16.3 does not restrict the set of available payment gateways to those enabled by the administrator, deriving it in part from request input, which allows unauthenticated users to complete donations through a payment gateway the administrator has disabled.
Title GiveWP < 4.16.3 - Unauthenticated Payment Gateway Restriction Bypass
References

Subscriptions

Givewp Givewp
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-07-31T13:35:13.963Z

Reserved: 2026-07-01T11:48:45.089Z

Link: CVE-2026-14317

cve-icon Vulnrichment

Updated: 2026-07-31T13:35:01.912Z

cve-icon NVD

Status : Received

Published: 2026-07-31T07:16:24.490

Modified: 2026-07-31T14:16:45.777

Link: CVE-2026-14317

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T11:45:03Z

Weaknesses