Phying News
Curated security research, vulnerabilities, advisories and tools for practitioners.

dinosn/givewp-cve-2026-82222-rce-lab: GiveWP CVE-2026-82222 RCE Docker Lab & PoC

Summary

A Docker lab reproducing CVE-2026-82222 in GiveWP 4.16.5.1: an unauthenticated PHP object-injection chain reaching marker command execution, with a constrained PoC; fixed in 4.16.7.2.

Why it matters

This research and reproducible lab validates a critical PHP object-injection POP chain in GiveWP, enabling security teams to test exposure, assess detections, and verify the 4.16.7.2 patch.
Vendor
GiveWP
Product
GiveWP Donation Plugin and Fundraising Platform for WordPress
Affected versions
4.16.5.1 and earlier; fixed in 4.16.7.2
CVSS
9.8
Published
Collected

original ↗

Related coverage

back