A maximum-severity vulnerability in the GiveWP plugin for WordPress allows an unauthenticated attacker to execute arbitrary commands on the hosting server.
The security issue is identified as CVE-2026–82222 and affects GiveWP through version 4.16.7.1. It was reported by bug researcher Udin Chan on July 28 through the Patchstack vulnerability intelligence platform.
The GiveWP plugin has more than 100,000 installs and allows collecting donations and managing fundraising campaigns.
