GiveWP < 4.16.8.1 - Unauthenticated Account Takeover via Donor Email Sanitization Mismatch
Summary
| CVE | CVE-2026-85530 |
|---|---|
| State | PUBLISHED |
| Assigner | WPScan |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-09-16 06:16:34 UTC |
| Updated | 2026-09-16 06:16:34 UTC |
| Description | The GiveWP WordPress plugin before 4.16.8.1 does not consistently normalise a donor's e-mail address between the value it stores and the value it later uses to look that donor up, allowing unauthenticated users to be resolved as an arbitrary donor and to set the WordPress password of any user account linked to one, including an administrator's. |
Risk And Classification
Problem Types: CWE-269 Improper Privilege Management
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| wpscan.com/vulnerability/83fcea02-345a-443c-b14e-316533a2fd7d | [email protected] | wpscan.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
CNA: Jakub Herman (en)
CNA: WPScan (en)
There are currently no legacy QID mappings associated with this CVE.