Impact
The defect is a missing authorization flaw (CWE‑862) in the StellarWP GiveWP plugin that permits bypassing configured access control rules. This flaw allows a user to access administrative functions that should normally be protected, potentially exposing or allowing manipulation of donation‑related features.
Affected Systems
WordPress installations that use the GiveWP plugin version 4.14.5 or earlier are affected. The issue applies to all releases of GiveWP managed by StellarWP up to and including version 4.14.5.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity. The EPSS score of less than 1 % reflects a very low probability of exploitation at the time of reporting, and the vulnerability is not listed in the CISA KEV catalog. The hypothetical attack vector is inferred to be a web‑based exploit that requires the attacker to send crafted HTTP requests to the plugin’s endpoints; no special network or local privileges are required to attempt the exploit.
OpenCVE Enrichment