Description
Authentication Bypass by Spoofing vulnerability in Liquid Web / StellarWP GiveWP give allows Identity Spoofing.This issue affects GiveWP: from n/a through 4.16.8.1.
Published: 2026-10-09
Score: 7.5 High
EPSS: n/a
KEV: No
Impact: Authentication Bypass
Action: Patch Now
AI Analysis

Impact

The GiveWP plugin contains an authentication bypass by spoofing flaw that allows an attacker to impersonate an authenticated user and bypass payment payment actions or changes to payment data, compromising the integrity and confidentiality of financial transactions.

Affected Systems

Liquid Web / StellarWP GiveWP for WordPress, versions up to and including 4.16.8.1. The issue is fixed in version 4.16.9 and later.

Risk and Exploitability

The CVSS score of 7.5 signals high severity. EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog. An attacker can exploit the flaw remotely by sending crafted requests to the plugin’s payment endpoints, bypassing normal authentication checks and potentially acting with the privileges of another user.

Generated by OpenCVE AI on October 9, 2026 at 12:29 UTC.

Remediation

Vendor Solution

Update the WordPress GiveWP plugin to the latest available version (at least 4.16.9).


OpenCVE Recommended Actions

  • Update the GiveWP plugin to the latest version (≥4.16.9).
  • Remove or deactivate any installed copies of versions older than 4.16.9 to ensure the vulnerable code cannot be loaded.
  • After the update, review and test the payment processing flow to confirm that authentication checks are functioning as intended; if a complete re‑deployment is not possible, consider blocking or limiting access to the plugin’s payment endpoints until the patch is applied.

Generated by OpenCVE AI on October 9, 2026 at 12:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 09 Oct 2026 10:15:00 +0000

Type Values Removed Values Added
Description Authentication Bypass by Spoofing vulnerability in Liquid Web / StellarWP GiveWP give allows Identity Spoofing.This issue affects GiveWP: from n/a through 4.16.8.1.
Title WordPress GiveWP plugin <= 4.16.8.1 - Payment Bypass vulnerability
Weaknesses CWE-290
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-10-09T10:00:16.516Z

Reserved: 2026-09-23T00:18:19.472Z

Link: CVE-2026-96333

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-09T10:16:44.460

Modified: 2026-10-09T10:16:44.460

Link: CVE-2026-96333

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-09T12:30:05Z

Weaknesses
  • CWE-290

    Authentication Bypass by Spoofing