CVE-2026-82222

Published Aug 28, 2026

Last updated 2 days ago

Overview

AI description

Automated description summarized from trusted sources.

CVE-2026-82222 is a PHP Object Injection vulnerability, categorized as CWE-502 (Deserialization of Untrusted Data), found in the GiveWP WordPress plugin. This flaw affects GiveWP versions up to and including 4.16.7.1. It allows unauthenticated remote attackers to inject malicious PHP objects through unsafe deserialization processes. Exploitation of this vulnerability can lead to remote code execution. The issue was addressed by the developers in GiveWP version 4.16.7.2, which blocks serialized data during donation processing and restricts object creation.

Description
Deserialization of Untrusted Data vulnerability in Liquid Web / StellarWP GiveWP allows Object Injection. This issue affects GiveWP: from n/a through 4.16.7.1.
Source
audit@patchstack.com
NVD status
Deferred

Risk scores

CVSS 3.1

Type
Secondary
Base score
10
Impact score
6
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Severity
CRITICAL

Weaknesses

audit@patchstack.com
CWE-502

Social media

Hype score is a measure of social media activity compared against trending CVEs from the past 12 months. Max score 100.

Hype score

12