Vulnerability
Published 2026-08-28
Verified 2026-09-19

GiveWP WordPress donation plugin unauthenticated RCE (CVE-2026-82222)

Patchstack (28 August 2026) and CVE-2026-82222 describe an unauthenticated PHP object injection chain in GiveWP through 4.16.7.1 that reaches remote code execution. On 4.16.5.1 and below a default install with one published donation form and an active gateway is enough. On 4.16.6–4.16.7.1 reachability narrows but a legacy give_forms post without formBuilderSettings (including draft/trashed) re-arms the chain. The plugin's give_action=user_register path ignores WordPress users_can_register, so an attacker can obtain an account even when registration is disabled. Patchstack rates CVSS 10.0. Vendor fixed in GiveWP 4.16.7.2 (27 August 2026), which breaks the chain at several layers and migrates serialized object payloads already in the database. Patch to 4.16.7.2 or later.

Product
GiveWP (WordPress plugin, Liquid Web / StellarWP)
Versions
Through 4.16.7.1
CVSS
(CVSS 3.1, Patchstack)
Exploited in Australia?
unknown
Patch to
4.16.7.2 or later

Primary: Patchstack advisory · Vendor: CVE-2026-82222 · CVE: CVE-2026-82222 · BleepingComputer (28 Aug; secondary)

vulnerabilities cloud