
[CIVN-2026-0434] Arbitrary Code Execution Vulnerability in GiveWP plugin for WordPress
—–BEGIN PGP SIGNED MESSAGE—–
Hash: SHA256
Arbitrary Code Execution Vulnerability in GiveWP plugin for WordPress
Indian – Computer Emergency Response Team (https://www.cert-in.org.in)
Severity Rating: CRITICAL
Software Affected
GiveWP plugin for WordPress versions prior to 4.16.7.2
Overview
A vulnerability has been identified in the GiveWP plugin for WordPress, which could allow an attacker to bypass security restrictions, inject malicious serialized objects into the session database, and execute arbitrary commands on the targeted system.
Target Audience:
All WordPress administrators and organizations utilizing the GiveWP plugin.
Risk Assessment:
Maximum risk of remote code execution leading to complete system compromise.
Impact Assessment:
Potential for full unauthorized control over the hosting server, sensitive data theft, and complete disruption of services.
Description
GiveWP is a widely used WordPress plugin designed to facilitate online donations and fundraising management.
This vulnerability exists in the GiveWP plugin due to unsafe deserialization of untrusted data, allowing PHP Object Injection that can lead to remote code execution. This vulnerability can be exploited through specially crafted HTTP requests. Attackers can bypass WordPress registration settings through an exposed unauthenticated action, obtain the necessary authentication, and subsequently trigger the exploit.
Successful exploitation of this vulnerability could allow an attacker to bypass security restrictions, inject malicious serialized objects into the session database, and execute arbitrary commands on the targeted system.
Solution
Apply appropriate fixes as mentioned in GiveWP plugin for WordPress:
https://www.bleepingcomputer.com/news/security/givewp-wordpress-donation-plugin-flaw-lets-hackers-execute-server-commands/
Vendor Information
https://www.bleepingcomputer.com/news/security/givewp-wordpress-donation-plugin-flaw-lets-hackers-execute-server-commands/
References
https://www.bleepingcomputer.com/news/security/givewp-wordpress-donation-plugin-flaw-lets-hackers-execute-server-commands/
CVE Name
CVE-2026-82222
– —
Thanks and Regards,
CERT-In
Incident Response Help Desk
e-mail: incident@cert-in.org.in
Phone: +91-11-22902657
Toll Free Number: 1800-11-4949
Toll Free Fax : 1800-11-6969
Web: http://www.cert-in.org.in
PGP Fingerprint: A768 083E 4475 5725 B81A A379 2156 C0C0 B620 D0B4
PGP Key information:
https://www.cert-in.org.in/s2cMainServlet?pageid=CONTACTUS
Postal address:
Indian Computer Emergency Response Team (CERT-In)
Ministry of Electronics and Information Technology
Government of India
Electronics Niketan
6, C.G.O. Complex
New Delhi-110 003
—–BEGIN PGP SIGNATURE—–
iQIzBAEBCAAdFiEE6r4Iam/Ey0c/KakL3jCgcSdcys8FAmqZiN8ACgkQ3jCgcSdc
ys962A/+Oaky8vZpNZKqwOnqJ8pF7A7O1oIZiNyyGlDZOLqD26M64QHD+UFmjuEL
eKAjufjk7LBRpxI/4LWu4AtgIcDy/euXG/z7z7nRNaUPpS56v4UXe0F/rScpbPMK
ScuRODBo8vvTKa7FyDj2Rob8nlTTWkeqkmhMXRKqRF/pDOKawKrNypVU6QfsmQft
QSRvyyQuApIvHmuqwhH70ZHREH3S6gfBTCQjqv5boPy2aA7m/g3wzVgtIDbtRLGK
f8ewQaiqzYZrF0IYqWF+1I/q2KRx3sa3jNO16D5XwC+RPPuJrnRo527braXOjovu
+xUeNKV+vTandgfnOObtVyhQ4RXC/6JFQB0tMgV/W/LLue4WH6JywOaaHrx05d+j
io2ifGSmVmCecsuMUZgb7FAdPrwm7zFydYSOdQ+u8xiIJWV+f81HnjqoVvXKw5S4
5mi7Gk2rYRDmo7S1ySCLQYOQb/Z1xp68F6dOX7L6j1x+YoFn0m038GxlQH3mVBCY
bjuP3wrNyyBKMteQEhq8/PDgj8zupX0EnNicuWzT07KtrFKvrFQkCuwKi94BYsLY
5DsGKmgcAN0KSKGLUtjUWDB12SXu5vs3/HH8N/oIpoxvrQukzIRLmU6+xXS29KMJ
7/Ye7YkD/xAWr9s21nGIqin2QIhgQbky4BhllAeY2CGMt79KCBw=
=Wltk
—–END PGP SIGNATURE—–


