Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 31 Jul 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-200 | |
| Metrics |
cvssV3_1
|
Fri, 31 Jul 2026 08:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Givewp
Givewp givewp Wordpress Wordpress wordpress |
|
| Vendors & Products |
Givewp
Givewp givewp Wordpress Wordpress wordpress |
Fri, 31 Jul 2026 06:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The GiveWP WordPress plugin before 4.16.3 does not properly restrict access to a REST API endpoint that returns recurring-donation records, allowing unauthenticated users to retrieve information about anonymous recurring donors, including their name and subscription details. | |
| Title | GiveWP < 4.16.3 - Unauthenticated Recurring Donor Information Disclosure | |
| References |
|
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2026-07-31T19:34:02.938Z
Reserved: 2026-07-01T11:48:49.247Z
Link: CVE-2026-14319
Updated: 2026-07-31T19:33:52.886Z
Status : Received
Published: 2026-07-31T07:16:24.593
Modified: 2026-07-31T20:16:46.290
Link: CVE-2026-14319
No data.
OpenCVE Enrichment
Updated: 2026-08-03T10:15:03Z
-
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor