The donation plugin lets strangers register on sites where registration is off — then run commands
2026-08-31Security
CVE-2026-82222 in GiveWP chains three weaknesses into unauthenticated command execution on the hosting server: an unsafe PHP unserialize helper, a donation flow that stores attacker-controlled objects, and a gadget chain in bundled libraries. Over 100,000 sites run it, and most of them belong to organisations with no security budget.