Sceawere
Vulnerability Detail
CVE-2026-97196UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
GiveWP Authentication Bypass Vulnerability
Vulnerability Metadata
- Severity
- Critical
- Score / CVSS
- 9.1
- Creation Date
- 3h ago
- Vendor
- Liquid Web / StellarWP
- Product
- GiveWP
- Attack Type
- CWE-1289 Improper Validation of Unsafe Equivalence in Input
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
Improper Validation of Unsafe Equivalence in Input vulnerability in Liquid Web / StellarWP GiveWP allows Authentication Bypass. This issue affects GiveWP: from n/a through 4.16.9.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "9.1",
"pubDate": "2026-09-30T07:16:31.320Z",
"pubdate": "2026-09-30T07:16:31.320Z",
"executiveSummary": "This vulnerability is categorized as an Improper Validation of Unsafe Equivalence issue within the GiveWP donation plugin for WordPress.\nThe flaw permits an unauthenticated attacker to bypass established authentication mechanisms, potentially granting unauthorized access to the application.\nThe vulnerability affects all GiveWP versions from n/a through 4.16.9.\nThe primary risk involves unauthorized account access or administrative actions, which can lead to complete site compromise depending on the user context obtained during the bypass.\nSuccessful exploitation requires no prior authentication, lowering the barrier to entry for attackers.\nThe vulnerability poses a severe threat to data integrity, confidentiality, and availability by allowing unauthorized actors to perform operations intended only for verified users or administrators.",
"technicalDetails": "The root cause of this vulnerability lies in the improper handling of input validation logic, specifically concerning how the application processes and compares equivalence during the authentication phase.\nIn the context of the GiveWP plugin, the affected authentication component fails to sufficiently validate input parameters, allowing an attacker to supply crafted input that the application erroneously evaluates as a valid session or identity token.\nBy exploiting the 'Improper Validation of Unsafe Equivalence' (CWE-843), the application's comparison logic is subverted, likely due to weak type checking or logical flaws in the authentication routine that allow an attacker to bypass the intended validation checks.\nThe attack flow commences with the adversary identifying the input parameters handled by the authentication routines within the GiveWP plugin. By submitting specially crafted payloads that manipulate the equivalence check—such as type-juggling or input substitution—the attacker can convince the application that they have successfully authenticated.\nBecause the validation logic is flawed, the server-side code proceeds to initialize a session for the attacker, assuming a legitimate authentication event has occurred. This effectively bypasses the requirement for valid credentials or existing session tokens.\nOnce the authentication mechanism is circumvented, the attacker inherits the privileges associated with the targeted user profile. If the vulnerability allows for the authentication of administrative accounts, the attacker gains full control over the GiveWP donation settings, donor data, and potentially the entire WordPress environment.\nThe vulnerability resides within the authentication flow of the plugin. As an unauthenticated exploit, it requires network access to the target WordPress instance. No privilege or user interaction is required from the victim side to trigger the flaw once the crafted request is delivered to the vulnerable endpoint.\nPost-exploitation impact includes unauthorized access to sensitive donor records, modification of donation settings, redirection of payment gateway configurations to attacker-controlled accounts, and the potential for persistent backdooring of the host CMS through administrative privileges."
}