---
id: CVE-2026-85530
title: >-
  The GiveWP  WordPress plugin before 4.16.8.1 does not consistently normalise a
  donor's e-mail address between the value it stores and the value it later uses
  to look that donor up, allowing unauthenticated users to be resolved as an
  arbi…
summary: >-
  The GiveWP  WordPress plugin before 4.16.8.1 does not consistently normalise a
  donor's e-mail address between the value it stores and the value it later uses
  to look that donor up, allowing unauthenticated users to be resolved as an
  arbi…
severity: high
cvss: 8.1
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-269
product: GiveWP
affected:
  - GiveWP >= 4.16.6 < 4.16.8.1
published: '2026-09-16'
updated: '2026-09-17'
sourceUpdated: '2026-09-17T13:16:50.963'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-85530'
references:
  - url: 'https://wpscan.com/vulnerability/83fcea02-345a-443c-b14e-316533a2fd7d/'
    label: contact@wpscan.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-09-17T12:18:58.515218Z'
epss: 0.00357
epssPercentile: 0.29448
ingestedAt: '2026-09-16T06:51:06.251Z'
---

## Overview

The GiveWP  WordPress plugin before 4.16.8.1 does not consistently normalise a donor's e-mail address between the value it stores and the value it later uses to look that donor up, allowing unauthenticated users to be resolved as an arbitrary donor and to set the WordPress password of any user account linked to one, including an administrator's.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
