Description
Unauthenticated Broken Access Control in GiveWP <= 4.16.5.1 versions.
Published: 2026-08-18
Score: 6.5 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an unauthenticated broken access control flaw that exists in GiveWP versions up to 4.16.5.1. Attackers can exploit this weakness to bypass normal authentication checks and gain unauthorized access to protected administrative functions of the plugin. The flaw is catalogued as CWE-862. Without proper safeguards, an attacker could manipulate donation forms, view or edit sensitive donor data, or potentially execute arbitrary actions that should be restricted to privileged users.

Affected Systems

Sites that use the GiveWP plugin before version 4.16.6 are affected, including deployments hosted by Nexcess. The plugin is a WordPress extension, so any WordPress installation that has GiveWP installed on these versions is vulnerable.

Risk and Exploitability

The CVSS score of 6.5 indicates a moderate severity. EPSS data is not available, so the current exploitation probability is uncertain, but the lack of authentication requirements and the plugin’s web‑based nature suggest that remote exploitation is possible. The issue is not listed in the CISA Known Exploited Vulnerabilities catalog, which reduces the likelihood of widespread targeted attacks at this time. Attackers would require only the plugin’s exposed administrative endpoints, making it a low‑barrier threat for anyone with internet access to the site.

Generated by OpenCVE AI on August 18, 2026 at 16:21 UTC.

Remediation

Vendor Solution

Update the WordPress GiveWP plugin to the latest available version (at least 4.16.6).


OpenCVE Recommended Actions

  • Update the GiveWP plugin to version 4.16.6 or later.
  • After updating, remove or restrict any unused GiveWP functions so only authorized administrators can access donation administration.
  • If a patch cannot be applied immediately, block unauthenticated access to the GiveWP admin endpoints using a web‑application firewall or server‑level access control rules.

Generated by OpenCVE AI on August 18, 2026 at 16:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 18 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
Description Unauthenticated Broken Access Control in GiveWP <= 4.16.5.1 versions.
Title WordPress GiveWP plugin <= 4.16.5.1 - Broken Access Control vulnerability
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-08-18T14:00:13.661Z

Reserved: 2026-08-12T10:51:20.620Z

Link: CVE-2026-73352

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-18T15:17:03.653

Modified: 2026-08-18T15:17:03.653

Link: CVE-2026-73352

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-18T16:30:05Z

Weaknesses