CVE-2026-97196: WordPress GiveWP plugin <= 4.16.9 - Broken Authentication vulnerability
Improper Validation of Unsafe Equivalence in Input vulnerability in Liquid Web / StellarWP GiveWP allows Authentication Bypass.
This issue affects GiveWP: from n/a through 4.16.9.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress GiveWP pluginto a version that resolves this vulnerability.Fixed in 4.17.0
Event History
Frequently Asked Questions
Which GiveWP installations are affected?
The issue affects GiveWP versions through 4.16.9. The available information does not identify any configuration prerequisite or unaffected earlier version.
Does an attacker need an account or user interaction to exploit this?
No. The CVSS vector indicates network exploitation with low attack complexity, no privileges required, and no user interaction required.
What is the likely impact of successful exploitation?
The vulnerability allows authentication bypass and is rated critical. The CVSS vector indicates high confidentiality and integrity impact, with no availability impact indicated.