Impact
This vulnerability is caused by an improper validation of unsafe equivalence in input data within the GiveWP plugin, allowing an attacker to bypass authentication checks without valid credentials. The flaw is extremely severe, reflected in the CVSS score of 9.1, indicating a high risk to confidentiality, integrity, and availability of the plugin’s administrative functions. Because the authentication mechanism is compromised, an attacker could gain unauthorized control over the plugin's interface, potentially affecting the entire WordPress site that hosts it.
Affected Systems
The flaw affects the Liquid Web / StellarWP GiveWP plugin for WordPress. Any installation using version 4.16.9 or earlier is vulnerable; all releases through 4.16.9 are impacted as stated by the vendor. Sites that have upgraded beyond 4.16.9 are not affected by this specific issue.
Risk and Exploitability
The CVSS score denotes a critical severity, and while no EPSS score is available, the absence of a KEV listing does not reduce the risk because the vulnerability is actively exploitable. Based on the nature of the flaw and typical attack patterns for authentication bypasses, the likely attack vector is an unauthenticated HTTP request to one of the plugin’s endpoints that is publicly accessible. This inference follows from the description that the vulnerability is due to improper input validation; therefore an attacker can trigger the flaw remotely over the web. Once exploitation succeeds, the attacker can impersonate an administrator and access protected areas of the plugin.
OpenCVE Enrichment