Phying News
Curated security research, vulnerabilities, advisories and tools for practitioners.
← back | CVE Intelligence

CVE-2026-82222 [Critical]

Curated 1 security research writeups, vulnerability advisories and exploitation analyses for CVE-2026-82222.

Vendor
GiveWP
Product
GiveWP Donation Plugin and Fundraising Platform for WordPress
Affected versions
4.16.5.1 and earlier; fixed in 4.16.7.2
CVSS
9.8
Coverage Span
2026-08-30
Reports
1 related reports

Associated Reports & Timeline

1.
github.com | research | | original ↗ | #rce | #php | #wordpress | #vulnerability
A Docker lab reproducing CVE-2026-82222 in GiveWP 4.16.5.1: an unauthenticated PHP object-injection chain reaching marker command execution, with a constrained PoC; fixed in 4.16.7.2.
Why it matters: This research and reproducible lab validates a critical PHP object-injection POP chain in GiveWP, enabling security teams to test exposure, assess detections, and verify the 4.16.7.2 patch.