Home › Intelligence › Brief
VULNERABILITY BRIEF🔴 Critical Vulnerability

Critical RCE Vulnerability (CVE‑2026‑82222) in GiveWP WordPress Donation Plugin Allows Unauthenticated Code Execution

A newly disclosed CVE‑2026‑82222 lets attackers create an account, inject malicious serialized objects, and run arbitrary commands on WordPress sites using the GiveWP donation plugin. The flaw bypasses registration controls and highlights the need for SOC 2‑aligned access‑control monitoring of third‑party components.

LiveThreat™ Intelligence · 📅 August 29, 2026· 📰 bleepingcomputer.com
🔴
Severity
Critical
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
2 sector(s)
✅
Actions
4 recommended
📰
Source
bleepingcomputer.com

GiveWP WordPress Donation Plugin Vulnerability Enables Unauthenticated Remote Code Execution (CVE‑2026‑82222)

What Happened — A critical remote‑code‑execution flaw (CVE‑2026‑82222) was discovered in the GiveWP donation plugin for WordPress. The vulnerability chains an unauthenticated registration endpoint, unsafe PHP unserialization, and a gadget chain to let an attacker execute arbitrary commands on the hosting server. The issue is patched in version 4.16.7.2 released 27 August 2026.

Why It Matters for Compliance & Audit Readiness

  • The flaw bypasses logical‑access controls, a core SOC 2 CC6.1 requirement; auditors will expect evidence that registration flows are hardened and that unauthenticated actions are prohibited.
  • Continuous monitoring of third‑party components (e.g., WordPress plugins) is essential to prove due‑diligence and maintain a defensible audit trail.
  • Remediation (patching, object‑validation hardening) provides concrete control evidence that can be captured in a SOC 2 readiness program.

Who Is Affected – Non‑profit organizations, charities, and any website that runs the GiveWP plugin (across sectors such as education, health, and civic tech).

Recommended Actions –

  • Upgrade to GiveWP 4.16.7.2 or later immediately.
  • Review WordPress users_can_register settings and disable any custom registration actions that bypass them.
  • Implement runtime monitoring for unexpected serialized objects in the wp_give_sessions table.
  • Map the remediation steps to SOC 2 Access Control (CC6.1) and capture evidence in your continuous‑compliance platform.

Technical Notes – The attack exploits three chained issues: an unauthenticated give_action=user_register endpoint, insecure deserialization of attacker‑controlled objects, and a gadget chain in bundled libraries that invokes system commands. Successful exploitation requires the attacker to first obtain an authentication cookie via the registration bypass. Source: BleepingComputer

📰 Original Source
https://www.bleepingcomputer.com/news/security/givewp-wordpress-donation-plugin-flaw-lets-hackers-execute-server-commands/ ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Misconfigurations are control gaps in disguise.

Verisq AI Trust Operations turns findings like this into mapped controls with continuous evidence, keeping your audit readiness current instead of point-in-time.

Map your controls with Verisq AI Trust Operations →