Vulnerability in GiveWP – Donation Plugin and Fundraising Platform — CVE-2026-106600
MediumSeverity
0.2%Estimated exploit probability
100,000+ sitesInstalls
4.18.0.1Fixed in
What to do now
Update GiveWP – Donation Plugin and Fundraising Platform to 4.18.0.1 or later.
Affected versions
- Everything up to and including 4.18.0
Affected: GiveWP – Donation Plugin and Fundraising Platform (plugin, give)
What the vulnerability is
The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, 4.18.0. This is due to a missing capability check on a function. This makes it possible for unauthenticated attackers to perform an unauthorized action.