2026-08-29 05:09 UTC
๐ค CVE-2026-82222 (max severity): RCE in the GiveWP WordPress donation plugin. Chain: unsafe unserialize + crafted donation + gadget โ arbitrary command execution. Unauthenticated attackers can register even when registration is disabled. Fixed in 4.16.7.2; 4.16.6โ4.16.7.1 vulnerable.
๐ https://www.bleepingcomputer.com/news/security/givewp-wordpress-donation-plugin-flaw-lets-hackers-execute-server-commands/
#CVE #RCE #WordPress #InfoSec
Replies (0)
No replies.