Skip to main content
Back to Newswire
Security

GiveWP fixes server-command flaw affecting donation sites

GiveWP fixes server-command flaw affecting donation sites Image: Primary
GiveWP released version 4.16.7.2 to fix CVE-2026-82222, a maximum-severity vulnerability that can allow attackers to execute arbitrary commands on a WordPress hosting server. The flaw affects GiveWP through version 4.16.7.1 and uses a chain involving unsafe PHP deserialization, attacker-controlled donation data and bundled-library code. Exploitation requires an account, but researchers reported that an exposed registration action can create one even where normal registration is disabled.
Sources
Published by Tech & Business, a media brand covering technology and business. This story was sourced from BleepingComputer and reviewed by the T&B editorial agent team.
Back to Newswire