GiveWP 4.16.7.2 security update for CVE-2026-82222
Security Patch Release
Summary
Hide ▲
Show ▼
GiveWP released version 4.16.7.2 on August 27 to fix CVE-2026-82222, a maximum-severity flaw in its WordPress donation plugin that allowed arbitrary command execution on hosting servers. The update blocks serialized data during donation processing, restricts object creation at deserialization points, and removes stored payloads from affected databases. Administrators running GiveWP through 4.16.7.1 are urged to install the patch immediately because exposed sites remain vulnerable until they upgrade.
Related Happenings
SimpleHelp security update for CVE-2026-48558
Security Patch Release
H score65
First: 15.06.2026 23:06
Last: 15.06.2026 23:06
Sources 1
About this happening:
SimpleHelp released 5.5.16 and 6.0 RC2 on June 9 to fix CVE-2026-48558, a critical OIDC authentication flaw in SimpleHelp remote management software th...
SimpleHelp security update for CVE-2026-48558
Security Patch ReleaseAbout this happening: SimpleHelp released 5.5.16 and 6.0 RC2 on June 9 to fix CVE-2026-48558, a critical OIDC authentication flaw in SimpleHelp remote management software th...
Progress security patch release for CVE-2026-2699
Security Patch Release
H score68
First: 02.04.2026 16:33
Last: 02.04.2026 16:33
Sources 1
About this happening:
Progress released ShareFile 5.12.4 on March 10 to fix CVE-2026-2699 and CVE-2026-2701 in the Storage Zones Controller (SZC) for branch 5.x. The update...
Progress security patch release for CVE-2026-2699
Security Patch ReleaseAbout this happening: Progress released ShareFile 5.12.4 on March 10 to fix CVE-2026-2699 and CVE-2026-2701 in the Storage Zones Controller (SZC) for branch 5.x. The update...
Elementor Ally 4.1.0 security patch release (CVE-2026-2313)
Security Patch Release
H score59
First: 11.03.2026 21:38
Last: 11.03.2026 21:38
Sources 1
About this happening:
Elementor released Ally 4.1.0 to fix CVE-2026-2313, a SQL injection flaw in the WordPress accessibility plugin that could expose sensitive data. The update lan...
Elementor Ally 4.1.0 security patch release (CVE-2026-2313)
Security Patch ReleaseAbout this happening: Elementor released Ally 4.1.0 to fix CVE-2026-2313, a SQL injection flaw in the WordPress accessibility plugin that could expose sensitive data. The update lan...
WPvivid Backup & Migration plugin security update 0.9.124 (CVE-2026-1357)
Security Patch Release
H score21
First: 12.02.2026 19:09
Last: 12.02.2026 19:09
Sources 1
About this happening:
WPVividPlugins released version 0.9.124 on January 28 to fix CVE-2026-1357 in the WPvivid Backup & Migration plugin for WordPress. The patch closes a critica...
WPvivid Backup & Migration plugin security update 0.9.124 (CVE-2026-1357)
Security Patch ReleaseAbout this happening: WPVividPlugins released version 0.9.124 on January 28 to fix CVE-2026-1357 in the WPvivid Backup & Migration plugin for WordPress. The patch closes a critica...
Veeam security patch release for CVE-2025-59470
Security Patch Release
H score34
First: 07.01.2026 15:06
Last: 07.01.2026 15:06
Sources 1
About this happening:
Veeam released version 13.0.1.1071 to patch Backup & Replication vulnerabilities, including CVE-2025-59470, a critical RCE flaw affecting 13.0.1.180 and earl...
Veeam security patch release for CVE-2025-59470
Security Patch ReleaseAbout this happening: Veeam released version 13.0.1.1071 to patch Backup & Replication vulnerabilities, including CVE-2025-59470, a critical RCE flaw affecting 13.0.1.180 and earl...
Timeline
-
28.08.2026 21:18 1 articles · 3h ago
Udin Chan reports CVE-2026-82222 in GiveWP
Initial DisclosureBug researcher Udin Chan reported CVE-2026-82222 in the GiveWP plugin for WordPress through Patchstack on July 28, identifying a maximum-severity flaw that could let an unauthenticated attacker execute arbitrary commands on the hosting server. Patchstack said exploitation could begin with an exposed unauthenticated registration action, even when WordPress registration is disabled.
Show sources
- GiveWP WordPress donation plugin flaw lets hackers execute server commands — www.bleepingcomputer.com — 28.08.2026 21:18
-
28.08.2026 21:18 2 articles · 3h ago
GiveWP ships version 4.16.7.2 to fix CVE-2026-82222
Mitigation Patch UpdateGiveWP released version 4.16.7.2 on August 27 to fix CVE-2026-82222 by blocking serialized data during donation processing and restricting object creation at several deserialization points.
Show sources
- GiveWP WordPress donation plugin flaw lets hackers execute server commands — www.bleepingcomputer.com — 28.08.2026 21:18
- GiveWP WordPress donation plugin flaw lets hackers execute server commands — www.bleepingcomputer.com — 28.08.2026 21:18