Impact
An unauthenticated broken access control flaw exists in GiveWP plugin versions earlier than 4.16.6, allowing an attacker to perform actions normally restricted to privileged users. The vulnerability is classified as CWE‑862. Access control failures can expose sensitive donation data, modify site settings, or grant unauthorized administrative capabilities, directly impacting confidentiality, integrity, and potentially availability of the affected WordPress installation.
Affected Systems
The affected product is the GiveWP WordPress plugin distributed by Nexcess. Versions prior to 4.16.6 are vulnerable. The plugin can be deployed on any WordPress site that installs or updates to these older releases.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate severity. The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog. Exploitation requires only standard public access to the vulnerable WordPress site – the flaw is unauthenticated – so the likely attack vector is remote exploitation via the web interface. No special conditions or privileged access are needed, but successful exploitation depends on an independent attacker having network reach to the target WordPress site.
OpenCVE Enrichment