SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-14317

MEDIUM · CVSS 5.3 EPSS 0.22%

Source: NVD + CISA KEV + EPSS · Published 2026-07-31 · Last synced 2026-08-30

CyberRota Analysis

AI-Generated

The GiveWP WordPress plugin prior to version 4.16.3 is vulnerable as it fails to restrict payment gateways based on administrator settings, allowing unauthenticated users to process donations through disabled gateways. This could lead to unauthorized transactions and potential financial loss for organizations relying on the plugin for donations. WordPress site administrators using the GiveWP plugin should prioritize updating to the latest version to mitigate this risk.

CVE
CVE-2026-14317
Severity
MEDIUM
CVSS
5.3
EPSS
0.22%
WordPress

Original NVD Description

The GiveWP WordPress plugin before 4.16.3 does not restrict the set of available payment gateways to those enabled by the administrator, deriving it in part from request input, which allows unauthenticated users to complete donations through a payment gateway the administrator has disabled.