


Perceptive Security
SOC/SIEM Consultancy

Deserialization of Untrusted Data vulnerability in Liquid Web / StellarWP GiveWP allows Object Injection.
This issue affects GiveWP: from n/a through 4.16.7.1.
Published:
28 August 2026 at 00:00:00
Alert date:
28 August 2026 at 18:01:32
Source:
nvd.nist.gov
Web Technologies, Zero-Day Vulnerabilities
A critical Deserialization of Untrusted Data vulnerability (CVE-2026-82222) has been identified in the GiveWP WordPress plugin developed by Liquid Web / StellarWP. The vulnerability allows unauthenticated attackers to perform PHP Object Injection, which can lead to Remote Code Execution (RCE) on affected systems. All versions of GiveWP up to and including 4.16.7.1 are affected. The flaw exists due to improper handling of untrusted serialized data, enabling attackers to inject malicious PHP objects without authentication. Successful exploitation could give attackers full control over the vulnerable WordPress installation. The issue has been documented by both the NVD and Patchstack, with Patchstack providing detailed technical analysis. WordPress site administrators using GiveWP are strongly advised to update to a patched version immediately. The vulnerability carries a high criticality rating given the unauthenticated nature of the attack vector and the potential for full system compromise.
Technical details
Mitigation steps:
Affected products:
GiveWP (up to 4.16.7.1)
WordPress
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-82222
https://patchstack.com/articles/unauthenticated-php-object-injection-to-remote-code-execution-on-givewp?_s_id=cve
https://patchstack.com/database/wordpress/plugin/give/vulnerability/wordpress-givewp-plugin-4-16-7-1-remote-code-execution-rce-vulnerability?_s_id=cve
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
