← Back to overview

A critical Deserialization of Untrusted Data vulnerability (CVE-2026-82222) has been identified in the GiveWP WordPress plugin developed by Liquid Web / StellarWP. The vulnerability allows unauthenticated attackers to perform PHP Object Injection, which can lead to Remote Code Execution (RCE) on affected systems. All versions of GiveWP up to and including 4.16.7.1 are affected. The flaw exists due to improper handling of untrusted serialized data, enabling attackers to inject malicious PHP objects without authentication. Successful exploitation could give attackers full control over the vulnerable WordPress installation. The issue has been documented by both the NVD and Patchstack, with Patchstack providing detailed technical analysis. WordPress site administrators using GiveWP are strongly advised to update to a patched version immediately. The vulnerability carries a high criticality rating given the unauthenticated nature of the attack vector and the potential for full system compromise.

Affected products

  • GiveWP (up to 4.16.7.1)
  • WordPress

Related CVE's

  • CVE-2026-82222

Categories

  • Web Technologies
  • Zero-Day Vulnerabilities