CVE-2026-96333: WordPress GiveWP plugin <= 4.16.8.1 - Payment Bypass vulnerability
Published Oct 9, 2026
·Updated
Authentication Bypass by Spoofing vulnerability in Liquid Web / StellarWP GiveWP give allows Identity Spoofing.This issue affects GiveWP: from n/a through 4.16.8.1.
Affected Software
1 affected component
Stellarwp GiveWP<=4.16.8.1
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress GiveWP pluginto a version that resolves this vulnerability.Fixed in 4.16.9
Event History
Oct 9, 2026
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
RemedyDescriptionSeverityWeakness