
A maximum severity vulnerability in the GiveWP plugin for WordPress allows an unauthenticated attacker to execute arbitrary commands on the hosting server.
The security issue is identified as CVE-2026-82222 and affects GiveWP up to version 4.16.7.1. This was reported on July 28 by bug researcher Udin Chan via vulnerability intelligence platform Patchstack.
The GiveWP plugin has more than 100,000 installs and allows you to collect donations and manage fundraisers.
Patchstack researchers explain that exploiting the vulnerability is possible by chaining three different problems:
- An insecure helper for deserializing PHP data
- A donation processing flow that stores serialized objects controlled by the attacker
- A gadget chain in libraries bundled with the plugin that can invoke arbitrary system commands
Successful exploitation depends on the attacker having an account on the target site. However, Patchstack says a disclosed, unauthenticated registration action allows account creation even if registration is disabled.
“(GiveWP) exposes an unauthenticated registration action (give_action=user_register) that never consults the WordPress “users_can_register” option.” Patch stack explained.
“Even on a website where registration is disabled, the attacker can create an account and receive an authentication cookie and then execute the rest of the attack in the same order.”
Once authenticated, hackers can store a malicious serialized object in their profile and inject it into the plugin’s session database by submitting a crafted donation.
“The server writes the gadget object to wp_give_sessions before returning an HTTP 500,” says George Johnstone, cybersecurity researcher at Patchstack.
By requesting any frontend page with the authentication cookie, the server deserializes the gadget and executes the attacker’s command.
Versions 4.16.6 through 4.16.7.1 remain vulnerable, although exploitation requires the site to contain an old donation form without formBuilderSettings.
Patchstack notes that such conditions may occur with updated installations, with websites using the plugin’s options-based form editor, or when importing or restoring older forms.
GiveWP fixed the vulnerability in version 4.16.7.2 released on August 27 by blocking serialized data during donation processing and restricting object creation at multiple deserialization points.
Additionally, the security update removes serialized object payloads that are already stored in affected databases.
However, Patchstack notes that GiveWP’s registration action still does not honor WordPress users’ registration settings, but this issue can no longer be exploited for code execution.
Website administrators using GiveWP are urged to apply the security updates as soon as possible to prevent malicious exploitation of CVE-2026-82222.
Last year, hackers targeted GiveWP to indirectly penetrate Pi-hole, a popular network-level ad blocker, revealing the names and email addresses of 30,000 donors.
Overall prevention scores can hide what happens after the first access. Once attackers use valid credentials, prevention drops sharply.
The 2026 Blue Report measures defense technology for technology in 338 million simulations conducted in customer production environments.


