Back

HIGH

GiveWP < 4.16.8.1 - Unauthenticated Account Takeover via Donor Email Sanitization Mismatch

Published Sep 16, 2026

Description

The GiveWP WordPress plugin before 4.16.8.1 does not consistently normalise a donor's e-mail address between the value it stores and the value it later uses to look that donor up, allowing unauthenticated users to be resolved as an arbitrary donor and to set the WordPress password of any user account linked to one, including an administrator's.

Affected products

Remediation

No remediation recorded yet.

Metrics

References (1)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner WPScan
Published Sep 16, 2026
Updated Sep 17, 2026
Reserved Sep 4, 2026
CISA Vulnrichment
Updated Sep 17, 2026
NVD
Status Deferred
Modified Sep 17, 2026
Red Hat
Severity n/a
Public date n/a