Critical GiveWP flaw allows unauthenticated attackers to execute server commands
A critical vulnerability, tracked as CVE-2026-82222, has been discovered in GiveWP, a popular WordPress donation plugin, affecting versions 4.16.7.1 and earlier. The flaw allows unauthenticated attackers to chain multiple weaknesses — including a registration bypass, PHP object injection via the last_name field, and a TCPDF gadget chain — to achieve remote code execution on vulnerable servers. Exploitation requires no user interaction and can be carried out entirely through API requests, making it particularly dangerous. Successful attacks could lead to theft of donor data and database credentials, installation of web shells, and lateral movement within the hosting environment. Site administrators are urged to update GiveWP to version 4.16.7.2 or later and audit their installations for suspicious accounts, sessions, and legacy forms.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in