patchstack.com
Critical RCE Vulnerability in GiveWP Plugin Patched
Article Content
GiveWP has addressed a critical unauthenticated PHP object injection vulnerability that can lead to remote code execution (RCE), rated CVSS 10. Discovered by Udin Chan and disclosed by Patchstack, the flaw affects versions 4.16.7.1 and below, allowing attackers to execute arbitrary commands without an account. The vulnerability exploits a broken safe unserialize helper in the plugin, which is widely used for online fundraising by nonprofits. GiveWP has over 100,000 active installations, making the impact significant. The patch, version 4.16.7.2, was released on August 25, 2026, after multiple failed patch attempts. While the RCE chain is closed, an unauthenticated registration issue remains, though it can no longer be exploited in conjunction with the RCE vulnerability. Users are urged to update immediately to mitigate risks.
Key Points: • Critical RCE vulnerability in GiveWP rated CVSS 10. • Patch released in version 4.16.7.2 on August 25, 2026. • Over 100,000 active installations of the affected plugin.
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.