The GiveWP WordPress plugin before 4.16.3 does not properly restrict access to a REST API endpoint that returns recurring-donation records, allowing unauthenticated users to retrieve information about anonymous recurring donors, including their name and subscription details.
Project Subscriptions
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Fri, 31 Jul 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-200 | |
| Metrics |
cvssV3_1
|
Fri, 31 Jul 2026 08:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Givewp
Givewp givewp Wordpress Wordpress wordpress |
|
| Vendors & Products |
Givewp
Givewp givewp Wordpress Wordpress wordpress |
Fri, 31 Jul 2026 06:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The GiveWP WordPress plugin before 4.16.3 does not properly restrict access to a REST API endpoint that returns recurring-donation records, allowing unauthenticated users to retrieve information about anonymous recurring donors, including their name and subscription details. | |
| Title | GiveWP < 4.16.3 - Unauthenticated Recurring Donor Information Disclosure | |
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2026-07-31T19:34:02.938Z
Reserved: 2026-07-01T11:48:49.247Z
Link: CVE-2026-14319
Updated: 2026-07-31T19:33:52.886Z
No data.
No data.
OpenCVE Enrichment
Updated: 2026-07-31T08:00:04Z
Weaknesses