Sceawere
Vulnerability Detail
CVE-2026-96834UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
GiveWP Subscriber Sensitive Data Exposure
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 6.5
- Creation Date
- 3h ago
- Vendor
- Nexcess
- Product
- GiveWP
- Attack Type
- CWE-862 Missing Authorization
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
Subscriber Sensitive Data Exposure in GiveWP <= 4.16.9 versions.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "6.5",
"pubDate": "2026-09-30T13:17:33.280Z",
"pubdate": "2026-09-30T13:17:33.280Z",
"executiveSummary": "The GiveWP plugin for WordPress, specifically versions 4.16.9 and below, contains a critical vulnerability involving the improper exposure of sensitive subscriber information. This security flaw is classified as an Insecure Direct Object Reference (IDOR) or Broken Access Control, allowing unauthenticated or low-privileged users to access restricted data that should remain private.\nThe vulnerability resides within the plugin's data handling mechanisms, where the implementation fails to verify the authorization level of the requester before serving sensitive records. An attacker can exploit this by manipulating requests to retrieve personal identifiable information (PII) related to donors and subscribers.\nThe potential impact of this vulnerability is severe, as it facilitates unauthorized data harvesting, potentially leading to mass privacy breaches, GDPR/CCPA non-compliance, and the exposure of sensitive donor history. The attack does not require complex infrastructure, only the ability to craft targeted HTTP requests directed at the vulnerable endpoints. Given that the vulnerability exists within the plugin’s core data processing logic, all installations running affected versions are considered at high risk. Organizations utilizing GiveWP are urged to restrict access or implement strict security controls until a patch is applied, as this vulnerability provides attackers with a direct pathway to exfiltrate confidential user data without administrative privileges.",
"technicalDetails": "The vulnerability originates from a deficiency in access control checks within the GiveWP data retrieval functions. Specifically, the plugin fails to enforce proper server-side authorization checks when handling requests to endpoints responsible for fetching subscriber or donor metadata. In a secure architecture, such requests should validate the session token and the user's privilege level (e.g., 'manage_options' or 'view_give_reports') against the requested resource ID.\nThe exploitation process typically leverages IDOR (Insecure Direct Object Reference) patterns. An attacker can identify a predictable or sequential parameter—such as a donor ID or subscriber record index—within the API request or the URL path. By iterating through these identifiers via automated scripts, an attacker can bypass the intended visibility restrictions. The application processes these requests and returns JSON-formatted sensitive data, assuming the requester has the authority to view the object based on its existence, rather than verifying the requester’s permission level.\nThe vulnerable component involves the plugin’s internal REST API endpoints or AJAX handlers that process data requests without sufficient capability verification. Because the plugin does not implement nonce validation or capability checks at the controller level for these specific endpoints, the data becomes exposed to any authenticated user, or in some configurations, unauthenticated actors, depending on the specific implementation of the endpoint's permission callback.\nStep-by-step attack flow: 1. The attacker intercepts or identifies the specific endpoint used by GiveWP to retrieve subscriber details. 2. The attacker crafts a request, altering the object ID parameter to target records belonging to other users. 3. Due to the lack of access control checks (e.g., current_user_can()), the backend server fulfills the request rather than returning a 403 Forbidden error. 4. The application returns the complete dataset, including PII such as names, email addresses, donation amounts, and potentially partial payment information. 5. The attacker exfiltrates this data systematically by cycling through the IDs in an automated fashion.\nThe impact is significant, as it leads to the unauthorized exposure of private donor information, which is subject to stringent data protection regulations. The lack of auditing or rate limiting on these endpoints further allows for the mass harvesting of database entries, leading to long-term privacy and security risks for the donor base."
}