CVE-2026-82222 is a CVSS 10.0 remote-code-execution flaw in the Liquid Web/StellarWP GiveWP WordPress donation plugin affecting versions through 4.16.7.1. Unsafe PHP deserialization can be combined with attacker-controlled donation-session metadata and a gadget chain in bundled TCPDF and GiveWP TestData components to invoke arbitrary server commands. Default installations with a public donation form and active payment gateway are exposed in versions 4.16.5.1 and earlier; later affected versions require specific legacy-form conditions.
GiveWP released 4.16.7.2 to block serialized donation data, restrict deserialization paths, validate gadget-related data, sanitize metadata, and remove previously stored serialized payloads from databases. Administrators should update immediately and review systems for suspicious donation-session records or unexpected server-side command execution. A separate registration-action access-control weakness can still create WordPress accounts while registration is disabled, but it no longer provides an RCE path after the deserialization fix.

See affected versions and whether adversaries are exploiting it.
5 events from the most recent confirmed update back to the earliest known activity.
Researcher Udin Chan reported the GiveWP insecure-deserialization vulnerability, later assigned CVE-2026-82222, to Patchstack. The flaw affects GiveWP through version 4.16.7.1 and can be chained into remote command execution.
Technical analysis found that CVE-2026-82222 can be exploited without an attacker account, user interaction, or administrator action. Default GiveWP installations through 4.16.5.1 may be directly exploitable with a published donation form, while versions 4.16.6 through 4.16.7.1 retain exploitable paths via legacy donation forms.
Technical reporting described how attackers can obtain an account through an exposed registration action, inject a malicious serialized object through the donation workflow, and trigger its deserialization when a front-end page is requested, resulting in server command execution. The report said more than 100,000 GiveWP installations running versions through 4.16.7.1 are affected.
Patchstack publicly released its advisory for CVE-2026-82222, an unauthenticated PHP object-injection issue in GiveWP that can enable remote code execution. The CVE record was also published and rated Critical with a CVSS v3.1 score of 10.0.
GiveWP released version 4.16.7.2 to address CVE-2026-82222, blocking serialized payloads in donation processing, restricting deserialization and gadget invocation, and removing previously stored serialized-object payloads from affected database records.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
6 references tracked. Mallory keeps watching after this page renders.
securityaffairs.com
Open sourcescworld.com
Open sourcebleepingcomputer.com
Open sourcecvefeed.io
Open sourcepatchstack.com
Open sourcepatchstack.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.