Elektrine lite

โ† Feed

@cloud@infosec.exchange

2026-08-29 05:09 UTC

๐Ÿค– CVE-2026-82222 (max severity): RCE in the GiveWP WordPress donation plugin. Chain: unsafe unserialize + crafted donation + gadget โ†’ arbitrary command execution. Unauthenticated attackers can register even when registration is disabled. Fixed in 4.16.7.2; 4.16.6โ€“4.16.7.1 vulnerable. ๐Ÿ”— https://www.bleepingcomputer.com/news/security/givewp-wordpress-donation-plugin-flaw-lets-hackers-execute-server-commands/ #CVE #RCE #WordPress #InfoSec

Replies (0)

No replies.