OCTOBER 6, 2026
Live Feed
Back to database
Case File

CVE-2026-97196

CRITICAL · CVSS 9.1 EPSS 0.30%

Source: NVD + CISA KEV + EPSS · Published 2026-09-30 · Last synced 2026-10-06

CyberRota Analysis

AI-Generated

An improper validation vulnerability in GiveWP allows for authentication bypass, potentially enabling unauthorized access to sensitive functionalities and data. This critical flaw affects all versions up to 4.16.9, making it imperative for users of GiveWP to prioritize immediate updates to mitigate the risk of exploitation. Organizations utilizing this plugin should assess their exposure and apply patches as soon as possible to safeguard their systems.

CVE
CVE-2026-97196
Severity
CRITICAL
CVSS
9.1
EPSS
0.30%

Original NVD Description

Improper Validation of Unsafe Equivalence in Input vulnerability in Liquid Web / StellarWP GiveWP allows Authentication Bypass. This issue affects GiveWP: from n/a through 4.16.9.