Find notable cyber news and cases, enriched with sources, timelines, and signals.

GiveWP 4.16.7.2 security update for CVE-2026-82222

Security Patch Release
First reported
Last updated
Happening score
H score 15
1 unique sources, 1 articles

Summary

Hide ▲

GiveWP released version 4.16.7.2 on August 27 to fix CVE-2026-82222, a maximum-severity flaw in its WordPress donation plugin that allowed arbitrary command execution on hosting servers. The update blocks serialized data during donation processing, restricts object creation at deserialization points, and removes stored payloads from affected databases. Administrators running GiveWP through 4.16.7.1 are urged to install the patch immediately because exposed sites remain vulnerable until they upgrade.

Related Happenings

SimpleHelp security update for CVE-2026-48558

Security Patch Release
H score65 First: 15.06.2026 23:06 Last: 15.06.2026 23:06 Sources 1

About this happening: SimpleHelp released 5.5.16 and 6.0 RC2 on June 9 to fix CVE-2026-48558, a critical OIDC authentication flaw in SimpleHelp remote management software th...

Progress security patch release for CVE-2026-2699

Security Patch Release
H score68 First: 02.04.2026 16:33 Last: 02.04.2026 16:33 Sources 1

About this happening: Progress released ShareFile 5.12.4 on March 10 to fix CVE-2026-2699 and CVE-2026-2701 in the Storage Zones Controller (SZC) for branch 5.x. The update...

Elementor Ally 4.1.0 security patch release (CVE-2026-2313)

Security Patch Release
H score59 First: 11.03.2026 21:38 Last: 11.03.2026 21:38 Sources 1

About this happening: Elementor released Ally 4.1.0 to fix CVE-2026-2313, a SQL injection flaw in the WordPress accessibility plugin that could expose sensitive data. The update lan...

WPvivid Backup & Migration plugin security update 0.9.124 (CVE-2026-1357)

Security Patch Release
H score21 First: 12.02.2026 19:09 Last: 12.02.2026 19:09 Sources 1

About this happening: WPVividPlugins released version 0.9.124 on January 28 to fix CVE-2026-1357 in the WPvivid Backup & Migration plugin for WordPress. The patch closes a critica...

Veeam security patch release for CVE-2025-59470

Security Patch Release
H score34 First: 07.01.2026 15:06 Last: 07.01.2026 15:06 Sources 1

About this happening: Veeam released version 13.0.1.1071 to patch Backup & Replication vulnerabilities, including CVE-2025-59470, a critical RCE flaw affecting 13.0.1.180 and earl...

Timeline

  1. 28.08.2026 21:18 1 articles · 3h ago

    Udin Chan reports CVE-2026-82222 in GiveWP

    Initial Disclosure

    Bug researcher Udin Chan reported CVE-2026-82222 in the GiveWP plugin for WordPress through Patchstack on July 28, identifying a maximum-severity flaw that could let an unauthenticated attacker execute arbitrary commands on the hosting server. Patchstack said exploitation could begin with an exposed unauthenticated registration action, even when WordPress registration is disabled.

    Show sources
  2. 28.08.2026 21:18 2 articles · 3h ago

    GiveWP ships version 4.16.7.2 to fix CVE-2026-82222

    Mitigation Patch Update

    GiveWP released version 4.16.7.2 on August 27 to fix CVE-2026-82222 by blocking serialized data during donation processing and restricting object creation at several deserialization points.

    Show sources