GiveWP WordPress donation plugin flaw lets hackers execute server commands
PatchGiveWPOur summary
The GiveWP donation plugin for WordPress has addressed a critical remote code execution vulnerability, identified as CVE-2026-82222, which allowed unauthenticated attackers to run arbitrary commands on hosting servers. This flaw affected versions up to 4.16.7.1 and exploited a combination of unsafe deserialization practices and a bypassable registration check to inject malicious serialized objects. The issue was resolved in version 4.16.7.2, released on August 27, which restricts object creation during donation processing and purges existing invalid payloads from databases.
BleepingComputer publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.