logo

GiveWP WordPress donation plugin flaw lets hackers execute server commands

ID: a17bb828-5172-55cd-aa9b-c365e8414993

STIX ID: report--a17bb828-5172-55cd-aa9b-c365e8414993

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2026-08-28

Date Updated: 2026-08-28

Author: Bill Toulas

...
...

A critical deserialization vulnerability (CVE-2026-82222) in the GiveWP WordPress donation plugin (≤ 4.16.7.1) allows unauthenticated attackers to create accounts via an exposed registration action, store malicious serialized objects, and achieve remote command execution on hosting servers; GiveWP released a fix in 4.16.7.2 that blocks serialized data and removes existing payloads. The issue affects sites with legacy donation forms and the plugin (100k+ installs), and administrators are urged to apply the update immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.