Unauthenticated Broken Access Control in GiveWP by WordPress
CVE-2026-73352

6.5MEDIUM

Key Information:

Vendor

WordPress

Status
Vendor
CVE Published:
18 August 2026

What is CVE-2026-73352?

A vulnerability in GiveWP prior to version 4.16.5.1 allows unauthenticated users to exploit broken access control mechanisms. This flaw can potentially give unauthorized access to sensitive actions or data, compromising the integrity of the platform. Site administrators are urged to update to the latest version to mitigate this security risk.

Affected Version(s)

GiveWP <= 4.16.5.1

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Dthangws | Patchstack Bug Bounty Program
.