WordPress Plugin Vulnerabilities

GiveWP < 4.16.8.1 - Unauthenticated Account Takeover via Donor Email Sanitization Mismatch

Description

The plugin does not consistently normalise a donor's e-mail address between the value it stores and the value it later uses to look that donor up, allowing unauthenticated users to be resolved as an arbitrary donor and to set the WordPress password of any user account linked to one, including an administrator's.

Proof of Concept

Affects Plugins

Fixed in 4.16.8.1

References

Classification

Miscellaneous

Original Researcher
Jakub Herman
Submitter
Jakub Herman
Submitter website
Verified
Yes

Timeline

Publicly Published
2026-09-14 (about 2 days ago)
Added
2026-09-14 (about 1 day ago)
Last Updated
2026-09-15 (about 7 hours ago)

Other