Sceawere

Vulnerability Detail

CVE-2026-97066UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Unauthenticated IDOR in GiveWP

Vulnerability Metadata

Severity
Medium
Score / CVSS
5.3
Creation Date
3h ago
Vendor
Nexcess
Product
GiveWP
Attack Type
CWE-639 Authorization Bypass Through User-Controlled Key
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Attack Complexity
LOW

Narrative and Response

Description

Unauthenticated Insecure Direct Object References (IDOR) in GiveWP <= 4.16.9 versions.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "5.3",
  "pubDate": "2026-09-30T13:17:34.080Z",
  "pubdate": "2026-09-30T13:17:34.080Z",
  "executiveSummary": "The GiveWP plugin, specifically in versions 4.16.9 and below, is susceptible to an Insecure Direct Object Reference (IDOR) vulnerability.\nThis vulnerability allows unauthenticated, remote attackers to access, modify, or delete sensitive data by manipulating object identifiers in requests.\nThe core issue stems from the application's failure to perform adequate authorization checks on user-supplied input when accessing backend resources.\nThe impact is significant, as it grants unauthorized actors access to protected donation data, personal information, or administrative configurations without requiring authentication.\nRisk implications include data breaches, loss of donor privacy, and potential site integrity compromise.\nExploitation requires no authentication and is accessible over a network, making this a high-severity flaw that demands immediate attention.\nAdministrators are urged to treat this as a critical security risk and prioritize patching or mitigation strategies immediately.",
  "technicalDetails": "The vulnerability is an Insecure Direct Object Reference (IDOR) within the GiveWP plugin (<= 4.16.9).\nIDOR occurs when an application exposes a reference to an internal implementation object—such as a file, directory, or database record—without implementing sufficient access control checks.\nIn the context of GiveWP, the application fails to validate the current user's authorization before serving, modifying, or acting upon requests referencing specific object IDs.\nAn unauthenticated attacker can interact with vulnerable endpoints by crafting HTTP requests that include predictable or enumerable parameters, such as donation IDs or user IDs.\nThe attack flow typically involves the following steps: 1. Reconnaissance: The attacker identifies the vulnerable endpoint responsible for handling sensitive data (e.g., retrieving donation records or processing user data). 2. Manipulation: The attacker sends a request to the endpoint, modifying the object reference parameter (e.g., changing an ID from '100' to '101') to target unintended records.\nBecause the application lacks server-side authorization checks for the requested object, it processes the request under the assumption that the caller has sufficient permissions, thereby returning or modifying unauthorized data.\nThe vulnerable component performs the requested action based solely on the user-supplied identifier, bypassing security constraints that should restrict access to authenticated administrators or authorized users only.\nThis exploitation does not require authentication, meaning any remote network user can interact with the vulnerable code path.\nPost-exploitation impact includes the unauthorized disclosure of sensitive donation information (PII), the ability to modify donation details, or potentially the unauthorized deletion of records depending on the functionality of the vulnerable endpoint.\nThe lack of integrity validation on these object references allows for large-scale enumeration of resources if the identifiers are sequential or guessable, amplifying the potential scope of the data breach."
}
CVE-2026-97066: Unauthenticated IDOR in GiveWP (MEDIUM Severity, CVSS: 5.3) | Sceawere