CVE-2026-104405: WordPress GiveWP plugin <= 4.17.0 - Privilege Escalation vulnerability
Published Oct 6, 2026
·Updated
Unauthenticated Privilege Escalation in GiveWP <= 4.17.0 versions.
Affected Software
1 affected component
GiveWP GiveWP<=4.17.0
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress GiveWP pluginto a version that resolves this vulnerability.Fixed in 4.18.0
Event History
Oct 6, 2026
CVE Published
via MITRE·08:35 AM
Data Sourced
via MITRE·08:35 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·09:17 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
The vulnerability is unauthenticated, so an attacker does not need a WordPress or GiveWP account. Exploitation is network-accessible, although the CVSS vector indicates high attack complexity.
2
Which installations are affected?
GiveWP versions up to and including 4.17.0 are affected. The available data does not identify any configuration prerequisite or mitigation setting.
3
What could successful exploitation allow?
Successful exploitation can result in privilege escalation and has high impacts on confidentiality, integrity, and availability according to the provided severity vector.