# GiveWP fixes server-command flaw affecting donation sites

_Thursday, August 27, 2026 at 2:18 PM EDT · Security · Latest · Tier 1 — Major_

![GiveWP fixes server-command flaw affecting donation sites — Primary](https://www.bleepstatic.com/content/hl-images/2023/12/07/back-2.jpg)

GiveWP released version 4.16.7.2 to fix CVE-2026-82222, a maximum-severity vulnerability that can allow attackers to execute arbitrary commands on a WordPress hosting server. The flaw affects GiveWP through version 4.16.7.1 and uses a chain involving unsafe PHP deserialization, attacker-controlled donation data and bundled-library code. Exploitation requires an account, but researchers reported that an exposed registration action can create one even where normal registration is disabled.

## Sources

- [BleepingComputer](https://www.bleepingcomputer.com/news/security/givewp-wordpress-donation-plugin-flaw-lets-hackers-execute-server-commands/)

---
Canonical: https://techandbusiness.org/newswire/PNb8QFYcesqObGo8Ojukvx
Retrieved: 2026-08-29T23:56:45.908Z
Publisher: Tech & Business (techandbusiness.org)
