Impact
The vulnerability is an unauthenticated broken access control flaw that exists in GiveWP versions up to 4.16.5.1. Attackers can exploit this weakness to bypass normal authentication checks and gain unauthorized access to protected administrative functions of the plugin. The flaw is catalogued as CWE-862. Without proper safeguards, an attacker could manipulate donation forms, view or edit sensitive donor data, or potentially execute arbitrary actions that should be restricted to privileged users.
Affected Systems
Sites that use the GiveWP plugin before version 4.16.6 are affected, including deployments hosted by Nexcess. The plugin is a WordPress extension, so any WordPress installation that has GiveWP installed on these versions is vulnerable.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate severity. EPSS data is not available, so the current exploitation probability is uncertain, but the lack of authentication requirements and the plugin’s web‑based nature suggest that remote exploitation is possible. The issue is not listed in the CISA Known Exploited Vulnerabilities catalog, which reduces the likelihood of widespread targeted attacks at this time. Attackers would require only the plugin’s exposed administrative endpoints, making it a low‑barrier threat for anyone with internet access to the site.
OpenCVE Enrichment