AI description
CVE-2026-82222 is a PHP Object Injection vulnerability, categorized as CWE-502 (Deserialization of Untrusted Data), found in the GiveWP WordPress plugin. This flaw affects GiveWP versions up to and including 4.16.7.1. It allows unauthenticated remote attackers to inject malicious PHP objects through unsafe deserialization processes. Exploitation of this vulnerability can lead to remote code execution. The issue was addressed by the developers in GiveWP version 4.16.7.2, which blocks serialized data during donation processing and restricts object creation.
- Description
- Deserialization of Untrusted Data vulnerability in Liquid Web / StellarWP GiveWP allows Object Injection. This issue affects GiveWP: from n/a through 4.16.7.1.
- Source
- audit@patchstack.com
- NVD status
- Deferred
CVSS 3.1
- Type
- Secondary
- Base score
- 10
- Impact score
- 6
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
- Severity
- CRITICAL
- audit@patchstack.com
- CWE-502
Hype score is a measure of social media activity compared against trending CVEs from the past 12 months. Max score 100.
- Hype score
12
RCE PoC for CVE-2026-82222 GiveWP (CVSS 10) https://t.co/2FxpdiFNt7 https://t.co/2JaZ7FK0fv
@Dinosn
30 Aug 2026
7297 Impressions
15 Retweets
73 Likes
36 Bookmarks
0 Replies
0 Quotes
🛡️ ExploitGrid Daily Threat Digest Top Vulnerabilities (CVEs) of the day CVE-2026-19295 - EXPLOIT CVE-2026-54745 CVE-2026-82222 CVE-2026-18527 CVE-2026-55565 ..🧵👇
@exploitgrid
29 Aug 2026
52 Impressions
0 Retweets
0 Likes
0 Bookmarks
1 Reply
0 Quotes