CVE-2026-73348: WordPress GiveWP plugin < 4.16.6 - Broken Access Control vulnerability
Published Aug 18, 2026
·Updated
Unauthenticated Broken Access Control in GiveWP < 4.16.6 versions.
Affected Software
1 affected component
WordPress GiveWP plugin<4.16.6
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress GiveWP pluginto a version that resolves this vulnerability.Fixed in 4.16.6
Event History
Aug 18, 2026
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this vulnerability?
Sites running GiveWP versions earlier than 4.16.6 are affected. The issue is network-accessible and does not require authentication or user interaction, according to the supplied CVSS vector.
2
What should I do to remediate it?
Update GiveWP to version 4.16.6 or later. No workaround or temporary mitigation is provided in the available data.
3
How can I determine whether my site is affected?
Check the installed GiveWP version on each WordPress site. Versions below 4.16.6 should be treated as affected.