CVE-2026-14319
GiveWP < 4.16.3 - Unauthenticated Recurring Donor Information Disclosure
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The GiveWP WordPress plugin before 4.16.3 does not properly restrict access to a REST API endpoint that returns recurring-donation records, allowing unauthenticated users to retrieve information about anonymous recurring donors, including their name and subscription details.
| Vendor | unknown |
| Product | givewp |
| Published | Jul 31, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown givewp
Be the first to know when new unknown vulnerabilities affecting unknown givewp are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / GiveWP
0 < 4.16.3
References
Credits
Sanjorn Keeratirungsan WPScan