top of page
perceptive_background_267k.jpg

Deserialization of Untrusted Data vulnerability in Liquid Web / StellarWP GiveWP allows Object Injection.

This issue affects GiveWP: from n/a through 4.16.7.1.

Published:

28 August 2026 at 00:00:00

Alert date:

28 August 2026 at 18:01:32

Source:

nvd.nist.gov

Click to open the original link from this advisory

Web Technologies, Zero-Day Vulnerabilities

A critical Deserialization of Untrusted Data vulnerability (CVE-2026-82222) has been identified in the GiveWP WordPress plugin developed by Liquid Web / StellarWP. The vulnerability allows unauthenticated attackers to perform PHP Object Injection, which can lead to Remote Code Execution (RCE) on affected systems. All versions of GiveWP up to and including 4.16.7.1 are affected. The flaw exists due to improper handling of untrusted serialized data, enabling attackers to inject malicious PHP objects without authentication. Successful exploitation could give attackers full control over the vulnerable WordPress installation. The issue has been documented by both the NVD and Patchstack, with Patchstack providing detailed technical analysis. WordPress site administrators using GiveWP are strongly advised to update to a patched version immediately. The vulnerability carries a high criticality rating given the unauthenticated nature of the attack vector and the potential for full system compromise.

Technical details

Mitigation steps:

Affected products:

GiveWP (up to 4.16.7.1)
WordPress

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Disclaimer: Deze website toont informatie afkomstig van externe bronnen. Perceptive aanvaardt geen verantwoordelijkheid voor de inhoud, juistheid of volledigheid van deze informatie.

bottom of page