GiveWP WordPress donation plugin flaw lets hackers execute server commands
ID: a17bb828-5172-55cd-aa9b-c365e8414993
STIX ID: report--a17bb828-5172-55cd-aa9b-c365e8414993
Feed Name: Bleeping Computer
A critical deserialization vulnerability (CVE-2026-82222) in the GiveWP WordPress donation plugin (≤ 4.16.7.1) allows unauthenticated attackers to create accounts via an exposed registration action, store malicious serialized objects, and achieve remote command execution on hosting servers; GiveWP released a fix in 4.16.7.2 that blocks serialized data and removes existing payloads. The issue affects sites with legacy donation forms and the plugin (100k+ installs), and administrators are urged to apply the update immediately.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
