Vulnerability Management

Critical vulnerability in GiveWP plugin allows remote code execution

(Credit: Bilal Ulker – stock.adobe.com)

A critical vulnerability in the GiveWP WordPress plugin, affecting over 100,000 installations, allows unauthenticated attackers to execute arbitrary commands on hosting servers. This security issue, identified as CVE-2026-82222, was reported on July 28 by bug researcher Udin Chan through the Patchstack vulnerability intelligence platform and has been addressed by the plugin developers, based on information published by Bleeping Computer.

The vulnerability, present in GiveWP versions up to 4.16.7.1, is exploitable by chaining three issues: an unsafe PHP data unserialization helper, a donation processing flow that stores attacker-controlled serialized objects, and a gadget chain within bundled libraries that enables arbitrary system command execution. While exploitation typically requires an attacker to have an account on the target site, an exposed unauthenticated registration action allows account creation even if registration is disabled. Attackers can then store a malicious serialized object in their profile and inject it into the plugin's session database via a crafted donation. The server unserializes this object upon requesting any front-end page, executing the attacker's command.

GiveWP addressed the vulnerability in version 4.16.7.2 by blocking serialized data during donation processing and restricting object creation. Website administrators are urged to update immediately.

Source: Bleeping Computer

Related Events

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds