CVE Tools

Unauthenticated PHP Object Injection to Remote Code Execution on GiveWP

PatchstackBy Patchstack10 min read

ResearchGiveWP WordPress Plugin

Our summary

GiveWP has released version 4.16.7.2 to remediate CVE-2026-82222, a critical vulnerability allowing unauthenticated attackers to achieve remote code execution on WordPress sites. The flaw stems from an unsafe unserialize helper that fails to neutralize malicious objects, combined with a gadget chain in the plugin's bundled libraries. Users of versions 4.16.7.1 and below, particularly those operating default installations or specific form configurations, should update immediately to close this attack vector.

Read at Patchstack

Below is the opening; the full story is at Patchstack.

From Patchstack


GiveWP

Unauthenticated PHP Object Injection to Remote Code Execution

This blog post is about an unauthenticated remote code execution vulnerability in the GiveWP plugin. An attacker with no account can run arbitrary commands on the server of a GiveWP site that has one published donation form and one active payment gateway which, on the versions where the chain is fully reachable, describes a default installation.…

Continue at Patchstack

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store