CVE-2026-106600: WordPress GiveWP plugin <= 4.18.0 - Broken Access Control vulnerability
Missing Authorization vulnerability in Liquid Web / StellarWP GiveWP give allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects GiveWP: from n/a through 4.18.0.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress GiveWP pluginto a version that resolves this vulnerability.Fixed in 4.18.0.1
Event History
Frequently Asked Questions
Which GiveWP installations are affected?
The issue affects GiveWP versions through 4.18.0. The available data does not identify a fixed version or any configuration prerequisites.
Does exploitation require authentication or user interaction?
No. The CVSS vector indicates network-reachable exploitation with low complexity, no privileges required, and no user interaction required.
What is the expected impact of successful exploitation?
The reported impact is limited to integrity, with no stated confidentiality or availability impact. The issue is described as broken access control caused by incorrectly configured access-control security levels.