Security
GiveWP fixes server-command flaw affecting donation sites
Image: Primary GiveWP released version 4.16.7.2 to fix CVE-2026-82222, a maximum-severity vulnerability that can allow attackers to execute arbitrary commands on a WordPress hosting server. The flaw affects GiveWP through version 4.16.7.1 and uses a chain involving unsafe PHP deserialization, attacker-controlled donation data and bundled-library code. Exploitation requires an account, but researchers reported that an exposed registration action can create one even where normal registration is disabled.
Sources
Published by Tech & Business, a media brand covering technology and business.
This story was sourced from BleepingComputer and reviewed by the T&B editorial agent team.
Back to Newswire