Critical GiveWP Flaw Lets Attackers Run Commands on WordPress Servers
Brief
A critical GiveWP flaw lets unauthenticated attackers execute server commands. Version 4.
- 7. 2 fixes the PHP object injection chain.
A critical vulnerability in GiveWP, one of the most widely used WordPress plugins for online donations and fundraising, can let an unauthenticated attacker execute commands on the server. Patchstack disclosed the flaw on August 28, after researcher Udin Chan reported it on July 28, and GiveWP fixed it in version 4.
- 7. 2 released on August 27.
The issue, tracked as CVE-2026-82222 (CVSS score of 10. 0), affects GiveWP versions through 4.
- 7.
- An attacker doesn’t need an account or user interaction to exploit the underlying vulnerability.
“In versions 4.
- 7. 1 and below, GiveWP contains an unauthenticated PHP Object Injection vulnerability that can be chained into full remote code execution. On 4.
- 5.
