A critical bug in the GiveWP donation plugin for WordPress could let attackers take over vulnerable websites and run commands on the hosting server. GiveWP says CVE-2026-82222 affects versions through 4.16.7.1 and was fixed in 4.16.7.2 on August 27. Patchstack says attackers can chain unsafe PHP deserialization, donation flow data handling, and bundled library gadget chains to achieve remote code execution, and can first create an account through an unauthenticated registration action even when site registration is disabled.
Why it matters: Organizations using GiveWP for fundraising should update immediately, because this flaw can lead to full server compromise. Sites with older or legacy donation forms may be especially exposed, and the update also removes malicious serialized payloads already stored in affected databases.
Bill Toulas
2026.08.28
100% relevant
This article appears to be the first tracked item establishing the specific GiveWP CVE-2026-82222 remote-code-execution flaw and its fix in version 4.16.7.2.
← Back to all stories