Description
WordPress Plugin GiveWP-Donation and Fundraising Platform is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently modify plugin settings. WordPress Plugin GiveWP-Donation and Fundraising Platform version 2.5.9 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 2.5.10 or latest
References
Related Vulnerabilities
Drupal Core 7.x Open Redirect (7.0 - 7.69)
WordPress 5.1.x Cross-Site Request Forgery (5.1)
Apache Traffic Server Stack-based Buffer Overflow Vulnerability (CVE-2026-58180)
WordPress Plugin Knight Lab Timeline Cross-Site Scripting (3.6.6)
axios Permissive List of Allowed Inputs Vulnerability (CVE-2026-42043)