[CIVN-2026-0434] Arbitrary Code Execution Vulnerability in GiveWP plugin for WordPress

By Published On: September 3, 2026

—–BEGIN PGP SIGNED MESSAGE—–

Hash: SHA256


Arbitrary Code Execution Vulnerability in GiveWP plugin for WordPress


Indian – Computer Emergency Response Team (https://www.cert-in.org.in)


Severity Rating: CRITICAL


Software Affected


GiveWP plugin for WordPress versions prior to 4.16.7.2

Overview


A vulnerability has been identified in the GiveWP plugin for WordPress, which could allow an attacker to bypass security restrictions, inject malicious serialized objects into the session database, and execute arbitrary commands on the targeted system.


Target Audience:

All WordPress administrators and organizations utilizing the GiveWP plugin.


Risk Assessment:

Maximum risk of remote code execution leading to complete system compromise.


Impact Assessment:

Potential for full unauthorized control over the hosting server, sensitive data theft, and complete disruption of services.


Description


GiveWP is a widely used WordPress plugin designed to facilitate online donations and fundraising management.


This vulnerability exists in the GiveWP plugin due to unsafe deserialization of untrusted data, allowing PHP Object Injection that can lead to remote code execution. This vulnerability can be exploited through specially crafted HTTP requests. Attackers can bypass WordPress registration settings through an exposed unauthenticated action, obtain the necessary authentication, and subsequently trigger the exploit.


Successful exploitation of this vulnerability could allow an attacker to bypass security restrictions, inject malicious serialized objects into the session database, and execute arbitrary commands on the targeted system.


Solution


Apply appropriate fixes as mentioned in GiveWP plugin for WordPress:

https://www.bleepingcomputer.com/news/security/givewp-wordpress-donation-plugin-flaw-lets-hackers-execute-server-commands/



Vendor Information


 

https://www.bleepingcomputer.com/news/security/givewp-wordpress-donation-plugin-flaw-lets-hackers-execute-server-commands/


References


 

https://www.bleepingcomputer.com/news/security/givewp-wordpress-donation-plugin-flaw-lets-hackers-execute-server-commands/


CVE Name

CVE-2026-82222




– —


Thanks and Regards,

CERT-In


Incident Response Help Desk

e-mail: incident@cert-in.org.in

Phone: +91-11-22902657

Toll Free Number: 1800-11-4949

Toll Free Fax : 1800-11-6969

Web: http://www.cert-in.org.in

PGP Fingerprint: A768 083E 4475 5725 B81A A379 2156 C0C0 B620 D0B4

PGP Key information:

https://www.cert-in.org.in/s2cMainServlet?pageid=CONTACTUS


Postal address:

Indian Computer Emergency Response Team (CERT-In)

Ministry of Electronics and Information Technology

Government of India

Electronics Niketan

6, C.G.O. Complex

New Delhi-110 003

—–BEGIN PGP SIGNATURE—–


iQIzBAEBCAAdFiEE6r4Iam/Ey0c/KakL3jCgcSdcys8FAmqZiN8ACgkQ3jCgcSdc

ys962A/+Oaky8vZpNZKqwOnqJ8pF7A7O1oIZiNyyGlDZOLqD26M64QHD+UFmjuEL

eKAjufjk7LBRpxI/4LWu4AtgIcDy/euXG/z7z7nRNaUPpS56v4UXe0F/rScpbPMK

ScuRODBo8vvTKa7FyDj2Rob8nlTTWkeqkmhMXRKqRF/pDOKawKrNypVU6QfsmQft

QSRvyyQuApIvHmuqwhH70ZHREH3S6gfBTCQjqv5boPy2aA7m/g3wzVgtIDbtRLGK

f8ewQaiqzYZrF0IYqWF+1I/q2KRx3sa3jNO16D5XwC+RPPuJrnRo527braXOjovu

+xUeNKV+vTandgfnOObtVyhQ4RXC/6JFQB0tMgV/W/LLue4WH6JywOaaHrx05d+j

io2ifGSmVmCecsuMUZgb7FAdPrwm7zFydYSOdQ+u8xiIJWV+f81HnjqoVvXKw5S4

5mi7Gk2rYRDmo7S1ySCLQYOQb/Z1xp68F6dOX7L6j1x+YoFn0m038GxlQH3mVBCY

bjuP3wrNyyBKMteQEhq8/PDgj8zupX0EnNicuWzT07KtrFKvrFQkCuwKi94BYsLY

5DsGKmgcAN0KSKGLUtjUWDB12SXu5vs3/HH8N/oIpoxvrQukzIRLmU6+xXS29KMJ

7/Ye7YkD/xAWr9s21nGIqin2QIhgQbky4BhllAeY2CGMt79KCBw=

=Wltk

—–END PGP SIGNATURE—–

Share this article