Last updated: September 29, 2026 at 8:42 AM UTC
All 891 Vulnerability 357 Breach 144 Threat 383 Defense 7
Tag: php-object-injection (1 article)Clear

Critical GiveWP WordPress flaw lets unauthenticated attackers run server commands

A critical flaw in GiveWP, a WordPress donation and fundraising plugin installed on more than 100,000 sites, lets an unauthenticated attacker run commands on the hosting server. Tracked as CVE-2026-82222, it chains three weaknesses: an unsafe PHP deserialization helper, a donation flow that stores attacker-controlled serialized objects, and a gadget chain in bundled libraries that turns that into system command execution. Although exploitation normally needs an account, an exposed registration action lets an attacker create one even when registration is disabled, making it effectively unauthenticated. It affects versions up to 4.16.7.1 and is fixed in 4.16.7.2, which blocks serialized data during donation processing.

Check
Update the GiveWP plugin to 4.16.7.2 across all WordPress sites now, and check for unexpected accounts, files, or processes on servers running the donation plugin.
Affected
WordPress sites running GiveWP up to 4.16.7.1 (CVE-2026-82222); an attacker can chain PHP object injection into system command execution, and a registration bypass makes exploitation effectively unauthenticated even with signups disabled.
Fix
Patch the plugin, put a web application firewall in front of the site, scan for web shells and unauthorized files, and review hosting accounts and logs on donation-enabled sites.