CVE-2026-85530: GiveWP < 4.16.8.1 - Unauthenticated Account Takeover via Donor Email Sanitization Mismatch
The GiveWP WordPress plugin before 4.16.8.1 does not consistently normalise a donor's e-mail address between the value it stores and the value it later uses to look that donor up, allowing unauthenticated users to be resolved as an arbitrary donor and to set the WordPress password of any user account linked to one, including an administrator's.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
GiveWP (WordPress plugin)to a version that resolves this vulnerability.Fixed in 4.16.8.1 - Operational
After upgrading GiveWP to 4.16.8.1, review for any unauthorized password changes caused by unauthenticated account takeover and reset passwords for affected accounts (including any administrator accounts).
Event History
Frequently Asked Questions
Which accounts are at risk of takeover?
Any WordPress user account linked to a GiveWP donor record may be affected, including administrator accounts. The issue allows an attacker to be resolved as an arbitrary donor and set the password for the linked WordPress account.
Does exploitation require authentication?
No. The issue is described as exploitable by unauthenticated users.
Which plugin versions are affected?
GiveWP versions before 4.16.8.1 are affected.