PatchSiren

GiveWP CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH GiveWP CVE published 2026-07-31

CVE-2026-14319

The GiveWP WordPress plugin before 4.16.3 has a vulnerability allowing unauthenticated users to retrieve information about anonymous recurring donors via a REST API endpoint. This issue has a CVSS score of 7.5 and is considered HIGH severity. The vulnerability impacts organizations using the GiveWP WordPress plugin, particularly those with anonymous recurring donors. Affected deployments should be identif [truncated]