GiveWP Flaw Lets Attackers Run Server Commands

BleepingComputer reported a maximum-severity flaw in the GiveWP WordPress donation plugin, tracked as CVE-2026-82222, that lets an unauthenticated attacker run arbitrary commands on the hosting server. That matters because the break is above WordPress itself: no login is needed, so normal WordPress access controls and admin-account protections do not block the path to host-level compromise. If the plugin is exposed on a server that also carries other apps or data, those neighboring assets can inherit the exposure too.

Part of the PlainSec briefing for 2026-08-29

Editions

Sources