WordPress Plugin Vulnerabilities

GiveWP < 4.16.3 - Unauthenticated Payment Gateway Restriction Bypass

Description

The plugin does not restrict the set of available payment gateways to those enabled by the administrator, deriving it in part from request input, which allows unauthenticated users to complete donations through a payment gateway the administrator has disabled.

Proof of Concept

Affects Plugins

Fixed in 4.16.3

References

Classification

Type
NO AUTHORISATION
CWE

Miscellaneous

Original Researcher
Revanth Hari Narayana Matte
Submitter
Revanth Hari Narayana Matte
Verified
Yes

Timeline

Publicly Published
2026-07-13 (about 18 days ago)
Added
2026-07-13 (about 17 days ago)
Last Updated
2026-07-13 (about 17 days ago)

Other