CVE-2026-85530
GiveWP < 4.16.8.1 - Unauthenticated Account Takeover via Donor Email Sanitization Mismatch
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The GiveWP WordPress plugin before 4.16.8.1 does not consistently normalise a donor's e-mail address between the value it stores and the value it later uses to look that donor up, allowing unauthenticated users to be resolved as an arbitrary donor and to set the WordPress password of any user account linked to one, including an administrator's.
| Vendor | unknown |
| Product | givewp |
| Published | Sep 16, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown givewp
Be the first to know when new unknown vulnerabilities affecting unknown givewp are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / GiveWP
4.16.6 < 4.16.8.1
References
Credits
Jakub Herman WPScan