CVE-2026-14319: GiveWP < 4.16.3 - Unauthenticated Recurring Donor Information Disclosure
The GiveWP WordPress plugin before 4.16.3 does not properly restrict access to a REST API endpoint that returns recurring-donation records, allowing unauthenticated users to retrieve information about anonymous recurring donors, including their name and subscription details.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
GiveWP WordPress pluginto a version that resolves this vulnerability.Fixed in 4.16.3
Event History
Frequently Asked Questions
Who is exposed to this issue?
Sites running the GiveWP WordPress plugin before version 4.16.3 are exposed if the affected REST API endpoint is reachable. An attacker does not need authentication or user interaction to retrieve the disclosed recurring-donor information.
What information can be disclosed?
The affected endpoint can return records for anonymous recurring donors, including donor names and subscription details.
How can I determine whether my site is affected?
Check the installed GiveWP plugin version. Versions earlier than 4.16.3 are affected; version 4.16.3 or later is not identified as affected by the provided information.