Unauthenticated PHP Object Injection to Remote Code Execution on GiveWP
ResearchGiveWP WordPress PluginOur summary
GiveWP has released version 4.16.7.2 to remediate CVE-2026-82222, a critical vulnerability allowing unauthenticated attackers to achieve remote code execution on WordPress sites. The flaw stems from an unsafe unserialize helper that fails to neutralize malicious objects, combined with a gadget chain in the plugin's bundled libraries. Users of versions 4.16.7.1 and below, particularly those operating default installations or specific form configurations, should update immediately to close this attack vector.
Below is the opening; the full story is at Patchstack.
From Patchstack
GiveWP
Unauthenticated PHP Object Injection to Remote Code Execution
This blog post is about an unauthenticated remote code execution vulnerability in the GiveWP plugin. An attacker with no account can run arbitrary commands on the server of a GiveWP site that has one published donation form and one active payment gateway which, on the versions where the chain is fully reachable, describes a default installation.…
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.