Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    GiveWP WordPress donation plugin flaw lets hackers execute server commands

    August 28, 2026

    Same Target, Different Playbooks: Two Attackers, Two Different Paths to Pwning the AI Stack | Blog

    August 28, 2026

    ICE Plans to Spends Millions on Boston Dynamics Dog Robots

    August 28, 2026
    Facebook X (Twitter) Instagram
    • Demos
    • Technology
    • Gaming
    • Buy Now
    Facebook X (Twitter) Instagram Pinterest Vimeo
    Canadian Cyber WatchCanadian Cyber Watch
    • Home
    • News
    • Alerts
    • Tips
    • Tools
    • Industry
    • Incidents
    • Events
    • Education
    Subscribe
    Canadian Cyber WatchCanadian Cyber Watch
    Home»News»GiveWP WordPress donation plugin flaw lets hackers execute server commands
    News

    GiveWP WordPress donation plugin flaw lets hackers execute server commands

    adminBy adminAugust 28, 2026No Comments3 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    Share
    Facebook Twitter LinkedIn Pinterest Email


    GiveWP WordPress donation plugin flaw lets hackers execute server commands

    A maximum-severity vulnerability in the GiveWP plugin for WordPress allows an unauthenticated attacker to execute arbitrary commands on the hosting server.

    The security issue is identified as CVE-2026-82222 and affects GiveWP through version 4.16.7.1. It was reported by bug researcher Udin Chan on July 28 through the Patchstack vulnerability intelligence platform.

    The GiveWP plugin has more than 100,000 installs and allows collecting donations and managing fundraising campaigns.

    image

    Patchstack researchers explain that exploiting the vulnerability is possible by chaining three distinct issues:

    1. An unsafe helper for unserializing PHP data
    2. A donation-processing flow that stores attacker-controlled serialized objects
    3. A gadget chain in libraries bundled with the plugin that can invoke arbitrary system commands

    Successful exploitation depends on the attacker having an account on the target site. However, Patchstack says that an exposed unauthenticated registration action allows creating an account even if registration is disabled.

    “[GiveWP] exposes an unauthenticated registration action (give_action=user_register) that never consults the WordPress users_can_register option,” Patchstack explains.

    “Even on a site that has registration disabled, the attacker can create an account and receive an authentication cookie, then carry out the rest of the attack in the same sequence.”

    After authentication, hackers can store a malicious serialized object in their profile and inject it into the plugin’s session database by submitting a crafted donation.

    “The server writes the gadget object into wp_give_sessions before returning an HTTP 500,” says George Johnstone, cybersecurity researcher at Patchstack.

    By requesting any front-end page with the authentication cookie, the server unserializes the gadget and executes the command from the attacker.

    Versions 4.16.6 through 4.16.7.1 remain vulnerable, although exploitation requires the site to contain a legacy donation form without ‘formBuilderSettings.’

    Patchstack comments that such conditions may exist in upgraded installations, sites using the plugin’s option-based form editor, or when importing or restoring older forms.

    GiveWP fixed the vulnerability in version 4.16.7.2, released on August 27, by blocking serialized data during donation processing and restricting object creation at several deserialization points.

    Additionally, the security update removes serialized object payloads already stored in affected databases.

    However, Patchstack notes that GiveWP’s registration action still does not honor WordPress user registration settings, but this issue is no longer exploitable for code execution.

    Website administrators using GiveWP are urged to apply the security updates as soon as possible to prevent malicious exploitation of CVE-2026-82222.

    Hackers targeted GiveWP last year to indirectly breach Pi-hole, a popular network-level ad-blocker, exposing the names and email addresses of 30,000 donors.


    article image

    Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply.

    The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments.

    Get the report



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleSame Target, Different Playbooks: Two Attackers, Two Different Paths to Pwning the AI Stack | Blog
    admin
    • Website

    Related Posts

    News

    Same Target, Different Playbooks: Two Attackers, Two Different Paths to Pwning the AI Stack | Blog

    August 28, 2026
    News

    ICE Plans to Spends Millions on Boston Dynamics Dog Robots

    August 28, 2026
    News

    Toy-making giant Hasbro disclose data breach affecting employees

    August 28, 2026
    Add A Comment

    Comments are closed.

    Demo
    Top Posts

    Catchy & Intriguing

    March 17, 202677 Views

    How fraudsters target credit unions

    May 4, 202643 Views

    IP Address Investigations and Local OSINT

    March 20, 202640 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews
    85
    Featured

    Pico 4 Review: Should You Actually Buy One Instead Of Quest 2?

    January 15, 2021 Featured
    8.1
    Uncategorized

    A Review of the Venus Optics Argus 18mm f/0.95 MFT APO Lens

    January 15, 2021 Uncategorized
    8.9
    Editor's Picks

    DJI Avata Review: Immersive FPV Flying For Drone Enthusiasts

    January 15, 2021 Editor's Picks

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Demo
    Most Popular

    Catchy & Intriguing

    March 17, 202677 Views

    How fraudsters target credit unions

    May 4, 202643 Views

    IP Address Investigations and Local OSINT

    March 20, 202640 Views
    Our Picks

    GiveWP WordPress donation plugin flaw lets hackers execute server commands

    August 28, 2026

    Same Target, Different Playbooks: Two Attackers, Two Different Paths to Pwning the AI Stack | Blog

    August 28, 2026

    ICE Plans to Spends Millions on Boston Dynamics Dog Robots

    August 28, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook X (Twitter) Instagram Pinterest
    • Home
    • Technology
    • Gaming
    • Phones
    • Buy Now
    © 2026 ThemeSphere. Designed by ThemeSphere.

    Type above and press Enter to search. Press Esc to cancel.