CVE-2026-14319

WordPress · GiveWP

The GiveWP WordPress plugin before 4.16.3 is vulnerable to an information exposure flaw, allowing unauthenticated attackers to access sensitive data.

Executive summary

An unauthenticated information exposure vulnerability in the GiveWP WordPress plugin poses a high risk of sensitive data compromise.

Vulnerability

The plugin contains an information exposure vulnerability (CWE-200) that allows unauthenticated remote attackers to access sensitive information through the application, as indicated by the CVSS vector.

Business impact

The exploitation of this vulnerability could lead to the unauthorized disclosure of sensitive donor or organizational data managed within the plugin. With a CVSS score of 7.5, the vulnerability is categorized as high severity, reflecting the potential for significant privacy breaches and regulatory non-compliance.

Remediation

Immediate Action: Update the GiveWP plugin to version 4.16.3 or later immediately to resolve the identified information exposure flaw.

Proactive Monitoring: Monitor server access logs for unusual requests targeting plugin-specific endpoints or patterns indicative of unauthorized data scraping.

Compensating Controls: Deploy a Web Application Firewall (WAF) with rules configured to block suspicious requests directed at the GiveWP plugin paths until the update is applied.

Exploitation status

Public Exploit Available: No confirmed public exploit (exploit_available: false).

Analyst recommendation

Given the high CVSS score and the existence of a proof-of-concept, organizations using the GiveWP plugin must prioritize patching. Failure to update to version 4.16.3 leaves the environment susceptible to information disclosure, which could result in severe reputational damage and data privacy liabilities.