


Perceptive Security
SOC/SIEM Consultancy

Deserialization of Untrusted Data vulnerability in Liquid Web / StellarWP GiveWP allows Object Injection.
This issue affects GiveWP: from n/a through 4.16.7.1.
Published:
28 augustus 2026 om 00:00:00
Alert date:
28 augustus 2026 om 15:08:13
Source:
nvd.nist.gov
Web Technologies, Zero-Day Vulnerabilities
A critical Deserialization of Untrusted Data vulnerability (CVE-2026-82222) has been identified in the GiveWP WordPress plugin developed by Liquid Web / StellarWP. The vulnerability allows unauthenticated attackers to perform PHP Object Injection, which can be escalated to Remote Code Execution (RCE). All versions of GiveWP up to and including 4.16.7.1 are affected. The flaw exists due to improper handling of untrusted serialized data. Exploitation does not require authentication, making it particularly dangerous for WordPress sites running the affected plugin. The vulnerability has been documented by both NVD and Patchstack. Site administrators are urged to update the plugin immediately to a patched version. The issue is classified as high severity given its unauthenticated RCE potential.
Technical details
Mitigation steps:
Affected products:
GiveWP (up to 4.16.7.1)
WordPress
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-82222
https://patchstack.com/articles/unauthenticated-php-object-injection-to-remote-code-execution-on-givewp?_s_id=cve
https://patchstack.com/database/wordpress/plugin/give/vulnerability/wordpress-givewp-plugin-4-16-7-1-remote-code-execution-rce-vulnerability?_s_id=cve
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
