This issue affects GiveWP: from n/a through 4.16.9.
Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
Update the WordPress GiveWP plugin to the latest available version (at least 4.17.0).
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 30 Sep 2026 07:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Improper Validation of Unsafe Equivalence in Input vulnerability in Liquid Web / StellarWP GiveWP allows Authentication Bypass. This issue affects GiveWP: from n/a through 4.16.9. | |
| Title | WordPress GiveWP plugin <= 4.16.9 - Broken Authentication vulnerability | |
| Weaknesses | CWE-1289 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: Patchstack
Published:
Updated: 2026-09-30T13:37:20.996Z
Reserved: 2026-09-24T08:49:59.808Z
Link: CVE-2026-97196
No data.
Status : Deferred
Published: 2026-09-30T07:16:31.320
Modified: 2026-09-30T14:18:14.160
Link: CVE-2026-97196
No data.
OpenCVE Enrichment
Updated: 2026-09-30T13:00:16Z
-
CWE-1289
Improper Validation of Unsafe Equivalence in Input