CVE-2026-42642: WordPress GiveWP plugin <= 4.14.5 - Broken Access Control vulnerability
Missing Authorization vulnerability in StellarWP GiveWP give allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects GiveWP: from n/a through <= 4.14.5.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-42642?
CVE-2026-42642 has been classified with a high severity level due to its potential for unauthorized access.
How do I fix CVE-2026-42642?
To fix CVE-2026-42642, upgrade to a version of the GiveWP plugin that is greater than 4.14.5.
What are the potential impacts of exploiting CVE-2026-42642?
Exploiting CVE-2026-42642 can lead to unauthorized actions being performed within the GiveWP plugin, compromising the security of the site.
Who is affected by CVE-2026-42642?
CVE-2026-42642 affects all installations of the GiveWP plugin version 4.14.5 and earlier.
Is CVE-2026-42642 an isolated issue or part of a broader vulnerability trend?
CVE-2026-42642 is indicative of a broader issue regarding broken access control in various applications, emphasizing the need for proper authorization checks.