CVE Tools

GiveWP WordPress donation plugin flaw lets hackers execute server commands

BleepingComputerBy Bill Toulas

PatchGiveWP

Our summary

The GiveWP donation plugin for WordPress has addressed a critical remote code execution vulnerability, identified as CVE-2026-82222, which allowed unauthenticated attackers to run arbitrary commands on hosting servers. This flaw affected versions up to 4.16.7.1 and exploited a combination of unsafe deserialization practices and a bypassable registration check to inject malicious serialized objects. The issue was resolved in version 4.16.7.2, released on August 27, which restricts object creation during donation processing and purges existing invalid payloads from databases.

Read at BleepingComputer

BleepingComputer publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store