CVE-2026-65464: WordPress GiveWP plugin <= 4.16.3 - Cross Site Request Forgery (CSRF) vulnerability
Published Jul 23, 2026
·Updated
Unauthenticated Cross Site Request Forgery (CSRF) in GiveWP <= 4.16.3 versions.
Affected Software
1 affected component
wordpress/givewp<=4.16.3
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress GiveWP pluginto a version that resolves this vulnerability.Fixed in 4.16.4
Event History
Jul 23, 2026
CVE Published
via MITRE·11:18 AM
Data Sourced
via MITRE·11:18 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·12:18 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-65464?
The severity of CVE-2026-65464 is rated as medium with a score of 5.4.
2
How do I fix CVE-2026-65464?
To fix CVE-2026-65464, update the GiveWP plugin to a version higher than 4.16.3.
3
What type of vulnerability is associated with CVE-2026-65464?
CVE-2026-65464 is associated with an unauthenticated Cross Site Request Forgery (CSRF) vulnerability.
4
Which software is affected by CVE-2026-65464?
The affected software for CVE-2026-65464 is the GiveWP plugin for WordPress.
5
What versions of GiveWP are impacted by CVE-2026-65464?
GiveWP versions up to and including 4.16.3 are impacted by CVE-2026-65464.