A maximum-severity flaw in the GiveWP WordPress plugin, tracked as CVE-2026-82222, can let an unauthenticated attacker achieve arbitrary command execution on the hosting server by chaining multiple vulnerabilities. GiveWP fixed the issue in version 4.16.7.2, and site administrators should update immediately to protect affected installations through 4.16.7.1. #GiveWP #CVE-2026-82222
Keypoints
- CVE-2026-82222 affects GiveWP through version 4.16.7.1.
- The flaw can lead to arbitrary command execution on the server.
- Exploitation chains unsafe unserialization, donation handling, and a gadget chain in bundled libraries.
- An unauthenticated registration action can let attackers create an account even when registration is disabled.
- GiveWP 4.16.7.2 blocks serialized data and removes stored payloads from affected databases.