Sceawere
Vulnerability Detail
CVE-2026-96333UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
GiveWP Identity Spoofing Vulnerability
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.5
- Creation Date
- 3h ago
- Vendor
- Liquid Web / StellarWP
- Product
- GiveWP
- Attack Type
- Authentication Bypass by Spoofing
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
Authentication Bypass by Spoofing vulnerability in Liquid Web / StellarWP GiveWP give allows Identity Spoofing.This issue affects GiveWP: from n/a through 4.16.8.1.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.5",
"pubDate": "2026-10-09T10:16:44.460Z",
"pubdate": "2026-10-09T10:16:44.460Z",
"executiveSummary": "The GiveWP plugin, developed by StellarWP, contains an authentication bypass vulnerability that facilitates identity spoofing. This security flaw allows unauthenticated or unauthorized actors to manipulate system processes to assume the identity of another user, potentially leading to unauthorized access to donor accounts, administrative functions, or sensitive transaction data.\nThe vulnerability affects all versions of GiveWP from the initial release through version 4.16.8.1. By exploiting this flaw, an attacker can bypass standard authentication mechanisms, effectively circumventing security controls designed to verify user identity. The risk implications are severe, as identity spoofing compromises the integrity of user accounts and may allow malicious actors to perform actions on behalf of legitimate users, such as altering donation settings, accessing personal information, or escalating privileges within the WordPress environment.\nThe exploitation of this vulnerability does not necessarily require complex access, relying instead on flaws within the application's authentication logic. Organizations utilizing the affected versions of GiveWP are at significant risk of unauthorized access and should prioritize immediate assessment and remediation.",
"technicalDetails": "The identified vulnerability in GiveWP stems from an implementation flaw within the plugin's authentication and session management logic, specifically facilitating identity spoofing. In web applications, identity spoofing occurs when an attacker successfully falsifies data, such as headers, cookies, or parameters, which the application uses to verify the identity of an active user session. In the case of GiveWP, the authentication mechanism fails to sufficiently validate the legitimacy of incoming requests or the integrity of user identity tokens during sensitive operations.\nThe root cause is likely an insecure handling of user-provided input that influences the identification of the current user context. When the application processes these inputs without proper server-side verification—such as signature validation for session tokens or strict matching of session state against the actual logged-in user—an attacker can inject forged identifiers. By crafting a request that mirrors the structure required by the authentication function, an adversary can convince the application that they are acting as a different, potentially higher-privileged user.\nThe attack flow typically follows a structured sequence: First, the attacker analyzes the application’s request structure to identify the parameters or tokens responsible for defining the user session. Second, the attacker prepares a malicious request, inserting the identifier (such as a User ID or an authentication hash) corresponding to the targeted user account. Third, the attacker transmits this crafted request to the vulnerable GiveWP component. If the application logic accepts the forged identity without validating its authenticity against a secure backend store, the application proceeds to treat the attacker's request as legitimate, granting the attacker the privileges associated with the targeted identity.\nGiven that this vulnerability affects versions up to 4.16.8.1, the attack surface covers any WordPress installation running the vulnerable GiveWP plugin. The impact is significant, as successful exploitation results in a complete bypass of authentication controls. This allows the attacker to view private donor information, interact with payment workflows, or, if the spoofed identity is an administrator, gain full control over the WordPress site installation. This vulnerability persists regardless of the underlying network configuration, as it is fundamentally a flaw in the application's software logic rather than the infrastructure."
}