CVE-2026-82222: WordPress GiveWP plugin <= 4.16.7.1 - Remote Code Execution (RCE) vulnerability
Deserialization of Untrusted Data vulnerability in Liquid Web / StellarWP GiveWP allows Object Injection.
This issue affects GiveWP: from n/a through 4.16.7.1.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress GiveWP pluginto a version that resolves this vulnerability.Fixed in 4.16.7.2
Event History
Frequently Asked Questions
Who can exploit this issue?
The supplied vector indicates that exploitation can be performed remotely over the network without authentication or user interaction. Attack complexity is rated low.
What impact could successful exploitation have?
Successful exploitation may result in remote code execution through PHP object injection. The provided severity vector rates confidentiality, integrity, and availability impact as high, with scope changed.
Which GiveWP versions are affected?
GiveWP versions through 4.16.7.1 are affected. The lower bound is listed as unspecified (n/a), so deployments should verify whether they run a version at or below 4.16.7.1.