CVE-2026-14319: GiveWP < 4.16.3 - Unauthenticated Recurring Donor Information Disclosure
The GiveWP WordPress plugin before 4.16.3 does not properly restrict access to a REST API endpoint that returns recurring-donation records, allowing unauthenticated users to retrieve information about anonymous recurring donors, including their name and subscription details.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
GiveWP WordPress pluginto a version that resolves this vulnerability.Fixed in 4.16.3