CVE-2026-96834: WordPress GiveWP plugin <= 4.16.9 - Sensitive Data Exposure vulnerability
Published Sep 30, 2026
·Updated
Subscriber Sensitive Data Exposure in GiveWP <= 4.16.9 versions.
Affected Software
1 affected component
GiveWP GiveWP<=4.16.9
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress GiveWP pluginto a version that resolves this vulnerability.Fixed in 4.17.0
Event History
Sep 30, 2026
CVE Published
via MITRE·12:27 PM
Data Sourced
via MITRE·12:27 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·01:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
The vulnerability is remotely reachable and requires Subscriber-level privileges. No user interaction is required.
2
What information could be exposed?
The issue is classified as sensitive data exposure with high confidentiality impact. The provided data does not identify the specific data fields or records that may be disclosed.
3
Is the plugin affected by default?
The available information identifies GiveWP versions up to and including 4.16.9 as affected, but does not state whether exploitation depends on a particular configuration or enabled feature.