Summary
GiveWP released a security update to fix a maximum-severity vulnerability (CVE-2026-82222) that allows unauthenticated attackers to execute remote code and take over WordPress servers.
Take Action:
If you run the GiveWP donation plugin on your WordPress site, update it to version 4.16.7.2 immediately. This flaw lets anyone take over your server without logging in, and the update also cleans out any malicious code already planted in your database. If you can't update immediately, put a web application firewall in front of the site to block PHP serialization attacks, and check your user accounts for any you didn't create.
Read the full article on BeyondMachines
This article was originally published on BeyondMachines
Top comments (0)