Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Airbus seeks US space unit sale as it shifts to European-built satellites

    August 29, 2026

    Open-weight AI companies are the Valley’s hottest acquisition targets

    August 29, 2026

    Hugging Face Unveils Microduck: A $399 Open-Source 25 cm Biped You Train with Reinforcement Learning

    August 29, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Airbus seeks US space unit sale as it shifts to European-built satellites
    • Open-weight AI companies are the Valley’s hottest acquisition targets
    • Hugging Face Unveils Microduck: A $399 Open-Source 25 cm Biped You Train with Reinforcement Learning
    • GiveWP WordPress donation plugin flaw lets hackers execute server commands
    • Bullish Backs USD.AI with $100M for AI Infrastructure Loans
    • Hà Đình Đức, guardian of Hanoi’s legendary turtle, died at 86
    • How the Rise of American Oligarchy Reshapes Geopolitics
    • Dolly Parton said she once lost look-alike contest to drag queen
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Saturday, August 29
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    GiveWP WordPress donation plugin flaw lets hackers execute server commands

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKAugust 29, 2026 Cybersecurity No Comments3 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    A maximum-severity vulnerability in the GiveWP plugin for WordPress allows an unauthenticated attacker to execute arbitrary commands on the hosting server.

    The security issue is identified as CVE-2026-82222 and affects GiveWP through version 4.16.7.1. It was reported by bug researcher Udin Chan on July 28 through the Patchstack vulnerability intelligence platform.

    The GiveWP plugin has more than 100,000 installs and allows collecting donations and managing fundraising campaigns.

    image

    Patchstack researchers explain that exploiting the vulnerability is possible by chaining three distinct issues:

    1. An unsafe helper for unserializing PHP data
    2. A donation-processing flow that stores attacker-controlled serialized objects
    3. A gadget chain in libraries bundled with the plugin that can invoke arbitrary system commands

    Successful exploitation depends on the attacker having an account on the target site. However, Patchstack says that an exposed unauthenticated registration action allows creating an account even if registration is disabled.

    “[GiveWP] exposes an unauthenticated registration action (give_action=user_register) that never consults the WordPress users_can_register option,” Patchstack explains.

    “Even on a site that has registration disabled, the attacker can create an account and receive an authentication cookie, then carry out the rest of the attack in the same sequence.”

    After authentication, hackers can store a malicious serialized object in their profile and inject it into the plugin’s session database by submitting a crafted donation.

    “The server writes the gadget object into wp_give_sessions before returning an HTTP 500,” says George Johnstone, cybersecurity researcher at Patchstack.

    By requesting any front-end page with the authentication cookie, the server unserializes the gadget and executes the command from the attacker.

    Versions 4.16.6 through 4.16.7.1 remain vulnerable, although exploitation requires the site to contain a legacy donation form without ‘formBuilderSettings.’

    Patchstack comments that such conditions may exist in upgraded installations, sites using the plugin’s option-based form editor, or when importing or restoring older forms.

    GiveWP fixed the vulnerability in version 4.16.7.2, released on August 27, by blocking serialized data during donation processing and restricting object creation at several deserialization points.

    Additionally, the security update removes serialized object payloads already stored in affected databases.

    However, Patchstack notes that GiveWP’s registration action still does not honor WordPress user registration settings, but this issue is no longer exploitable for code execution.

    Website administrators using GiveWP are urged to apply the security updates as soon as possible to prevent malicious exploitation of CVE-2026-82222.

    Hackers targeted GiveWP last year to indirectly breach Pi-hole, a popular network-level ad-blocker, exposing the names and email addresses of 30,000 donors.


    article image

    Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply.

    The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments.

    Get the report

    Commands Donation Execute Flaw GiveWP hackers lets Plugin server WordPress
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    The Vulnpocalypse Is Repricing the Bug Bounty Economy

    ownCloud Flaw Exploited to Steal Nuclear Records From Philippine Research Body

    You Need Cyber Deception for OT

    Berlin Refuses to Pay Hackers Who Stole Data From the City’s State Network

    PaperCut releases second emergency patch for exploited flaws

    McKesson discloses breach after ShinyHunters claims patient data theft

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Airbus seeks US space unit sale as it shifts to European-built satellites

    August 29, 2026

    Open-weight AI companies are the Valley’s hottest acquisition targets

    August 29, 2026

    Hugging Face Unveils Microduck: A $399 Open-Source 25 cm Biped You Train with Reinforcement Learning

    August 29, 2026

    GiveWP WordPress donation plugin flaw lets hackers execute server commands

    August 29, 2026
    Latest Posts

    NASA Awards 2026 Innovative Technology Concepts

    July 30, 2026

    Microsoft Quietly Adds New Windows App That Wants to Scan Your Face

    July 30, 2026

    US Bans Foreign-Made Humanoid Robots, Targeting China Over National Security

    July 30, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Airbus seeks US space unit sale as it shifts to European-built satellites

    August 29, 2026

    Open-weight AI companies are the Valley’s hottest acquisition targets

    August 29, 2026

    Hugging Face Unveils Microduck: A $399 Open-Source 25 cm Biped You Train with Reinforcement Learning

    August 29, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.