CVE-2026-97066: WordPress GiveWP plugin <= 4.16.9 - Insecure Direct Object References (IDOR) vulnerability
Published Sep 30, 2026
·Updated
Unauthenticated Insecure Direct Object References (IDOR) in GiveWP <= 4.16.9 versions.
Affected Software
1 affected component
GiveWP GiveWP<=4.16.9
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress GiveWP pluginto a version that resolves this vulnerability.Fixed in 4.17.0
Event History
Sep 30, 2026
CVE Published
via MITRE·12:27 PM
Data Sourced
via MITRE·12:27 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·01:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What access does an attacker need to exploit this issue?
The issue is described as unauthenticated, so exploitation does not require an authenticated WordPress or GiveWP account. The attack vector is network-based and requires no user interaction.
2
What is the likely security impact?
The supplied CVSS vector indicates integrity impact only, with no stated confidentiality or availability impact. The overall severity is medium with a CVSS score of 5.3.
3
Which GiveWP versions are identified as affected?
GiveWP versions up to and including 4.16.9 are identified as affected. The provided data does not identify a fixed version.