Impact
The GiveWP plugin contains an authentication bypass by spoofing flaw that allows an attacker to impersonate an authenticated user and bypass payment payment actions or changes to payment data, compromising the integrity and confidentiality of financial transactions.
Affected Systems
Liquid Web / StellarWP GiveWP for WordPress, versions up to and including 4.16.8.1. The issue is fixed in version 4.16.9 and later.
Risk and Exploitability
The CVSS score of 7.5 signals high severity. EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog. An attacker can exploit the flaw remotely by sending crafted requests to the plugin’s payment endpoints, bypassing normal authentication checks and potentially acting with the privileges of another user.
OpenCVE Enrichment