Impact
The vulnerability stems from inconsistent normalisation of a donor's e‑mail address. GiveWP stores the email in one format but later uses a different normalized form when looking up the donor. An unauthenticated request can therefore resolve to an arbitrary donor record and reset the WordPress password of any user whose account is linked to that donor, including administrators. This is a remote authentication bypass that can lead to full control over the site.
Affected Systems
GiveWP WordPress plugin versions older than 4.16.8.1 are impacted. No additional vendor or product details are available. Sites using this plugin should verify the installed version and ensure it is not one of the affected releases.
Risk and Exploitability
The EPSS score is below 1 %, indicating exploitation probability is low, and the vulnerability is not listed in CISA's KEV catalog. However, the impact is severe – an attacker who exploits it can assume any user account. The attack vector requires no authentication and relies only on submitting a crafted e‑mail address through the plugin’s public interfaces. Successful exploitation would allow password reset of linked accounts and thereby uncontrolled access.
OpenCVE Enrichment