What is CVE-2026-14317?
This vulnerability exists in the GiveWP WordPress plugin before version 4.16.3, where the set of available payment gateways is partially derived from request input without restriction. It allows unauthenticated users to complete donations using a payment gateway disabled by the administrator. Updating the plugin to version 4.16.3 or later is recommended.
Azərbaycanca: Bu boşluq GiveWP WordPress plaginində (4.16.3-dən əvvəl) aşkarlanıb və autentifikasiya olunmamış istifadəçilərə administrator tərəfindən deaktiv edilmiş ödəniş şlüzləri vasitəsilə ianə tamamlamağa imkan verir. Səbəb, aktivləşdirilmiş ödəniş metodlarının sorğu daxilolmalarına əsasən müəyyən edilməsi və məhdudlaşdırılmamasıdır. Plugini ən azı 4.16.3 versiyasına yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
What does the CVE-2026-14317 vulnerability in GiveWP allow?
It allows unauthenticated users to complete donations using a payment gateway that has been disabled by an administrator.
How can I protect against CVE-2026-14317?
It is recommended to update the GiveWP plugin to version 4.16.3 or later.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.