top of page
perceptive_background_267k.jpg

Deserialization of Untrusted Data vulnerability in Liquid Web / StellarWP GiveWP allows Object Injection.

This issue affects GiveWP: from n/a through 4.16.7.1.

Published:

28 augustus 2026 om 00:00:00

Alert date:

28 augustus 2026 om 15:08:13

Source:

nvd.nist.gov

Click to open the original link from this advisory

Web Technologies, Zero-Day Vulnerabilities

A critical Deserialization of Untrusted Data vulnerability (CVE-2026-82222) has been identified in the GiveWP WordPress plugin developed by Liquid Web / StellarWP. The vulnerability allows unauthenticated attackers to perform PHP Object Injection, which can be escalated to Remote Code Execution (RCE). All versions of GiveWP up to and including 4.16.7.1 are affected. The flaw exists due to improper handling of untrusted serialized data. Exploitation does not require authentication, making it particularly dangerous for WordPress sites running the affected plugin. The vulnerability has been documented by both NVD and Patchstack. Site administrators are urged to update the plugin immediately to a patched version. The issue is classified as high severity given its unauthenticated RCE potential.

Technical details

Mitigation steps:

Affected products:

GiveWP (up to 4.16.7.1)
WordPress

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page