CyberRota Analysis
AI-GeneratedThe GiveWP WordPress plugin prior to version 4.16.3 is vulnerable as it fails to restrict payment gateways based on administrator settings, allowing unauthenticated users to process donations through disabled gateways. This could lead to unauthorized transactions and potential financial loss for organizations relying on the plugin for donations. WordPress site administrators using the GiveWP plugin should prioritize updating to the latest version to mitigate this risk.
Original NVD Description
The GiveWP WordPress plugin before 4.16.3 does not restrict the set of available payment gateways to those enabled by the administrator, deriving it in part from request input, which allows unauthenticated users to complete donations through a payment gateway the administrator has disabled.