CVE-2026-82222 is an insecure PHP deserialization vulnerability in Liquid Web / StellarWP GiveWP through version 4.16.7.1. GiveWP's deserialization handling used PHP unserialization with class instantiation disabled, but accepted resulting incomplete objects and later reserialized them, preserving attacker-controlled object properties and class metadata. An attacker can place a serialized payload in donor-profile metadata, cause it to be persisted through donation-session processing, and trigger a later unrestricted deserialization path. A gadget chain involving TCPDF destruction behavior and GiveWP TestData ProviderForwarder dispatch reaches call_user_func_array with an attacker-controlled callable, allowing invocation of system().
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
No public exploits tracked yet. Mallory keeps watching.
No public exploit code observed for this vulnerability.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
15 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A critical unauthenticated arbitrary system command-execution vulnerability in the GiveWP WordPress plugin. It chains unsafe PHP deserialization, attacker-controlled serialized-object storage during donation processing, and a bundled-library gadget chain. Attackers can create an account through an exposed registration action, inject a malicious serialized object through a crafted donation, and trigger command execution when a front-end page causes the server to unserialize the object.
A maximum-severity remote code execution vulnerability in the GiveWP WordPress plugin. Attackers can abuse an exposed registration action to create an account even where site registration is disabled, submit a crafted donation that stores a malicious serialized object in the plugin session database, and trigger unsafe deserialization through a front-end request to execute arbitrary system commands.
An insecure deserialization vulnerability in Liquid Web / StellarWP GiveWP that permits object injection. It affects GiveWP versions through 4.16.7.1.
A CVSS 10.0 critical unauthenticated network-reachable insecure deserialization/object-injection vulnerability in the WordPress GiveWP plugin through version 4.16.7.1, described as enabling remote code execution.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.