What is CVE-2026-14319?
CVE-2026-14319 affects the GiveWP WordPress plugin before version 4.16.3, where an improperly restricted REST API endpoint allows unauthenticated users to access recurring-donation records, exposing anonymous donors' names and subscription details. Users must update to the latest version immediately.
Azərbaycanca: CVE-2026-14319, GiveWP WordPress plaginində REST API endpoint-inin düzgün məhdudlaşdırılmaması səbəbindən autentifikasiya olunmamış şəxslərə anonim donorların ad və abunəlik məlumatlarını əldə etməyə imkan verir. Plaginin 4.16.3-dən əvvəlki versiyaları təsirlənir və inzibatçılar dərhal ən son versiyaya yeniləməlidir.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
Which versions of the GiveWP plugin are affected by CVE-2026-14319?
CVE-2026-14319 affects the GiveWP WordPress plugin before version 4.16.3.
What information can unauthenticated users access through this vulnerability?
Unauthenticated users can access anonymous donors' names and subscription details.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.