Unauthenticated Privilege Escalation in GiveWP Plugin by WordPress
CVE-2026-104405
8.1HIGH
What is CVE-2026-104405?
The GiveWP plugin for WordPress, specifically in versions up to 4.17.0, is susceptible to an unauthenticated privilege escalation vulnerability. This flaw allows attackers to gain elevated permissions without authentication, potentially compromising the integrity and functionality of the WordPress site. It highlights the importance of updating to secure versions to mitigate risks associated with unauthorized access.
Affected Version(s)
GiveWP <= 4.17.0