← Terug naar overzicht

A critical Deserialization of Untrusted Data vulnerability (CVE-2026-82222) has been identified in the GiveWP WordPress plugin developed by Liquid Web / StellarWP. The vulnerability allows unauthenticated attackers to perform PHP Object Injection, which can be escalated to Remote Code Execution (RCE). All versions of GiveWP up to and including 4.16.7.1 are affected. The flaw exists due to improper handling of untrusted serialized data. Exploitation does not require authentication, making it particularly dangerous for WordPress sites running the affected plugin. The vulnerability has been documented by both NVD and Patchstack. Site administrators are urged to update the plugin immediately to a patched version. The issue is classified as high severity given its unauthenticated RCE potential.

Affected products

  • GiveWP (up to 4.16.7.1)
  • WordPress

Related CVE's

  • CVE-2026-82222

Categories

  • Web Technologies
  • Zero-Day Vulnerabilities