GiveWP WordPress Donation Plugin Vulnerability Enables Unauthenticated Remote Code Execution (CVE‑2026‑82222)
What Happened — A critical remote‑code‑execution flaw (CVE‑2026‑82222) was discovered in the GiveWP donation plugin for WordPress. The vulnerability chains an unauthenticated registration endpoint, unsafe PHP unserialization, and a gadget chain to let an attacker execute arbitrary commands on the hosting server. The issue is patched in version 4.16.7.2 released 27 August 2026.
Why It Matters for Compliance & Audit Readiness
- The flaw bypasses logical‑access controls, a core SOC 2 CC6.1 requirement; auditors will expect evidence that registration flows are hardened and that unauthenticated actions are prohibited.
- Continuous monitoring of third‑party components (e.g., WordPress plugins) is essential to prove due‑diligence and maintain a defensible audit trail.
- Remediation (patching, object‑validation hardening) provides concrete control evidence that can be captured in a SOC 2 readiness program.
Who Is Affected – Non‑profit organizations, charities, and any website that runs the GiveWP plugin (across sectors such as education, health, and civic tech).
Recommended Actions –
- Upgrade to GiveWP 4.16.7.2 or later immediately.
- Review WordPress
users_can_registersettings and disable any custom registration actions that bypass them. - Implement runtime monitoring for unexpected serialized objects in the
wp_give_sessionstable. - Map the remediation steps to SOC 2 Access Control (CC6.1) and capture evidence in your continuous‑compliance platform.
Technical Notes – The attack exploits three chained issues: an unauthenticated give_action=user_register endpoint, insecure deserialization of attacker‑controlled objects, and a gadget chain in bundled libraries that invokes system commands. Successful exploitation requires the attacker to first obtain an authentication cookie via the registration bypass. Source: BleepingComputer