Impact
This vulnerability allows an attacker to bypass access controls without authentication, potentially granting them full control over the GiveWP plugin’s administrative functions. The flaw is a pure access control failure and can lead to unauthorized data manipulation, disclosure, or deletion within the WordPress site. The impact is that any user with network access can exploit the weakness to perform actions normally restricted to privileged staff, thereby compromising the integrity and confidentiality of donation transactions and user data.
Affected Systems
The issue affects the GiveWP WordPress plugin from the Nexcess vendor. Versions earlier than 4.16.6 are vulnerable; newer releases contain the fix. Systems running these older versions of the plugin on any WordPress installation are at risk.
Risk and Exploitability
The CVSS score of 6.5 reflects a moderate severity of this access-control flaw. Because the patch is not listed in CISA KEV and the EPSS score is unavailable, the overall exploitation likelihood is uncertain but not dismissed. Based on the description, the likely attack vector is an unauthenticated network user sending crafted requests to endpoints that lack proper authorization checks. Attackers would need only network connectivity to engage the vulnerable plugin.
OpenCVE Enrichment