Critical RCE Vulnerability in GiveWP Plugin Patched

Critical RCE Vulnerability in GiveWP Plugin Patched

First seen 28 Aug 2026, 14:53 UTC Therepository.Emailpatchstack.com 70.5

Article Content

Browse articles
ThreatCluster

GiveWP has addressed a critical unauthenticated PHP object injection vulnerability that can lead to remote code execution (RCE), rated CVSS 10. Discovered by Udin Chan and disclosed by Patchstack, the flaw affects versions 4.16.7.1 and below, allowing attackers to execute arbitrary commands without an account. The vulnerability exploits a broken safe unserialize helper in the plugin, which is widely used for online fundraising by nonprofits. GiveWP has over 100,000 active installations, making the impact significant. The patch, version 4.16.7.2, was released on August 25, 2026, after multiple failed patch attempts. While the RCE chain is closed, an unauthenticated registration issue remains, though it can no longer be exploited in conjunction with the RCE vulnerability. Users are urged to update immediately to mitigate risks.

Key Points: • Critical RCE vulnerability in GiveWP rated CVSS 10. • Patch released in version 4.16.7.2 on August 25, 2026. • Over 100,000 active installations of the affected plugin.

Timeline

2026-07-28
Vulnerability reported
Udin Chan reported the unauthenticated PHP object injection vulnerability to Patchstack.
Therepository.Email
2026-08-25
Patch released
GiveWP released version 4.16.7.2 to address the critical RCE vulnerability.
Therepository.Email
2026-08-28
Public disclosure
Patchstack disclosed the vulnerability and mitigation measures in a blog post.
patchstack.com