CVE-2026-14319
UNKNOWN
NVD
CVSS Score
0
Severity
UNKNOWN
Published
Jul 31, 2026
Vendor
unknown
Description
The GiveWP WordPress plugin before 4.16.3 does not properly restrict access to a REST API endpoint that returns recurring-donation records, allowing unauthenticated users to retrieve information about anonymous recurring donors, including their name and subscription details.