Sceawere

Vulnerability Detail

CVE-2026-96834UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

GiveWP Subscriber Sensitive Data Exposure

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.5
Creation Date
3h ago
Vendor
Nexcess
Product
GiveWP
Attack Type
CWE-862 Missing Authorization
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Attack Complexity
LOW

Narrative and Response

Description

Subscriber Sensitive Data Exposure in GiveWP <= 4.16.9 versions.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.5",
  "pubDate": "2026-09-30T13:17:33.280Z",
  "pubdate": "2026-09-30T13:17:33.280Z",
  "executiveSummary": "The GiveWP plugin for WordPress, specifically versions 4.16.9 and below, contains a critical vulnerability involving the improper exposure of sensitive subscriber information. This security flaw is classified as an Insecure Direct Object Reference (IDOR) or Broken Access Control, allowing unauthenticated or low-privileged users to access restricted data that should remain private.\nThe vulnerability resides within the plugin's data handling mechanisms, where the implementation fails to verify the authorization level of the requester before serving sensitive records. An attacker can exploit this by manipulating requests to retrieve personal identifiable information (PII) related to donors and subscribers.\nThe potential impact of this vulnerability is severe, as it facilitates unauthorized data harvesting, potentially leading to mass privacy breaches, GDPR/CCPA non-compliance, and the exposure of sensitive donor history. The attack does not require complex infrastructure, only the ability to craft targeted HTTP requests directed at the vulnerable endpoints. Given that the vulnerability exists within the plugin’s core data processing logic, all installations running affected versions are considered at high risk. Organizations utilizing GiveWP are urged to restrict access or implement strict security controls until a patch is applied, as this vulnerability provides attackers with a direct pathway to exfiltrate confidential user data without administrative privileges.",
  "technicalDetails": "The vulnerability originates from a deficiency in access control checks within the GiveWP data retrieval functions. Specifically, the plugin fails to enforce proper server-side authorization checks when handling requests to endpoints responsible for fetching subscriber or donor metadata. In a secure architecture, such requests should validate the session token and the user's privilege level (e.g., 'manage_options' or 'view_give_reports') against the requested resource ID.\nThe exploitation process typically leverages IDOR (Insecure Direct Object Reference) patterns. An attacker can identify a predictable or sequential parameter—such as a donor ID or subscriber record index—within the API request or the URL path. By iterating through these identifiers via automated scripts, an attacker can bypass the intended visibility restrictions. The application processes these requests and returns JSON-formatted sensitive data, assuming the requester has the authority to view the object based on its existence, rather than verifying the requester’s permission level.\nThe vulnerable component involves the plugin’s internal REST API endpoints or AJAX handlers that process data requests without sufficient capability verification. Because the plugin does not implement nonce validation or capability checks at the controller level for these specific endpoints, the data becomes exposed to any authenticated user, or in some configurations, unauthenticated actors, depending on the specific implementation of the endpoint's permission callback.\nStep-by-step attack flow: 1. The attacker intercepts or identifies the specific endpoint used by GiveWP to retrieve subscriber details. 2. The attacker crafts a request, altering the object ID parameter to target records belonging to other users. 3. Due to the lack of access control checks (e.g., current_user_can()), the backend server fulfills the request rather than returning a 403 Forbidden error. 4. The application returns the complete dataset, including PII such as names, email addresses, donation amounts, and potentially partial payment information. 5. The attacker exfiltrates this data systematically by cycling through the IDs in an automated fashion.\nThe impact is significant, as it leads to the unauthorized exposure of private donor information, which is subject to stringent data protection regulations. The lack of auditing or rate limiting on these endpoints further allows for the mass harvesting of database entries, leading to long-term privacy and security risks for the donor base."
}
CVE-2026-96834: GiveWP Subscriber Sensitive Data Exposure (MEDIUM Severity, CVSS: 6.5) | Sceawere