CVE-2026-85530
Received Received - Intake

Authentication Bypass in GiveWP Donor Email Handling

Vulnerability report for CVE-2026-85530, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-16

Last updated on: 2026-09-16

Assigner: WPScan

Description

The GiveWP WordPress plugin before 4.16.8.1 does not consistently normalise a donor's e-mail address between the value it stores and the value it later uses to look that donor up, allowing unauthenticated users to be resolved as an arbitrary donor and to set the WordPress password of any user account linked to one, including an administrator's.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-16
Last Modified
2026-09-16
Generated
2026-10-07
AI Q&A
2026-09-16
EPSS Evaluated
2026-10-05
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
givewp givewp to 4.16.8.1 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The GiveWP WordPress plugin before version 4.16.8.1 has a flaw where donor email addresses are not consistently normalized between storage and lookup. This allows unauthenticated users to manipulate email addresses to impersonate any donor, including resetting passwords for linked accounts such as administrators.

Detection Guidance

Check the installed version of the GiveWP plugin using WordPress admin panel or via command line with: wp plugin list | grep givewp. If the version is below 4.16.8.1, the system is vulnerable.

Impact Analysis

This vulnerability enables attackers to take over any user account linked to a donor, including administrator accounts. They can reset passwords and gain full control of the WordPress site, leading to potential data breaches, unauthorized access, and complete site compromise.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive user data, violating GDPR and HIPAA requirements for data protection and access control. Organizations may face legal penalties, reputational damage, and loss of compliance certifications due to potential data breaches.

Mitigation Strategies

Update the GiveWP plugin to version 4.16.8.1 or later immediately. Disable the plugin temporarily if an update is not possible. Review user accounts for unauthorized changes.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-85530. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart