Skip to main content
QUIETLYTIC
Vulnerability

GiveWP Insecure Deserialization (CVE-2026-82222)

CVE-2026-82222 is a CVSS 10.0 deserialization flaw in the GiveWP WordPress donation plugin through 4.16.7.1, reported as exploited by VulnCheck's KEV catalog.

CVE-2026-82222
Threat Level
CRITICAL
CVSS
10.0
Status
Active Exploitation
Confidence
Medium
Affected Products
GiveWP, Liquid Web / StellarWP GiveWP (through 4.16.7.1)

CVE-2026-82222 carries a CVSS 3.1 base score of 10.0 — the maximum — against GiveWP, a WordPress donation and fundraising plugin. NVD classifies it as CWE-502 (Deserialization of Untrusted Data) and records that the issue affects GiveWP releases up to and including 4.16.7.1. VulnCheck’s KEV feed reports the CVE as exploited, dated August 31, 2026.

One qualification belongs in the first paragraph rather than a footnote: that exploitation report is single-sourced. CISA has not added CVE-2026-82222 to its Known Exploited Vulnerabilities catalog as of our most recent CISA KEV ingestion on September 16, 2026. VulnCheck maintains a broader exploited-vulnerability catalog than CISA’s, drawing on vendor and researcher reporting that CISA’s own listing criteria may not yet have admitted. The practical consequence is that no US federal remediation obligation under Binding Operational Directive 26-04 attaches to this CVE — that directive is triggered by CISA KEV listing, not by exploitation as such.

What the flaw is

NVD describes an untrusted-deserialization weakness that permits object injection. PHP object injection is the language-specific form of CWE-502: where an application reconstructs objects from data it received rather than data it controls, an attacker who can influence that serialized input can influence which objects come into existence and what happens when they are later used or destroyed. The consequences depend on what classes the surrounding codebase makes available, which is why the same underlying bug can range from harmless to full code execution across different installations of the same software.

NVD’s own record stops at “allows Object Injection” and does not itself assert remote code execution. The Patchstack advisories that NVD links as references are titled in terms of object injection leading to remote code execution, which is indirect evidence of the more severe outcome — strong enough to plan around, not a claim NVD makes. We are reporting the distinction rather than collapsing it, because the two framings imply different urgency.

Why the score is 10.0 and not 9.8

Worth understanding, because it recurs across this batch. The vector is AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H. Every metric there is at its worst plausible setting, but the one doing the work is S:C — scope changed, meaning the assessed impact crosses out of the vulnerable component into resources managed by a different security authority. For a WordPress plugin that assessment is defensible: the plugin runs inside the host site’s PHP process, so compromising it reaches the whole site rather than only the plugin’s own data. A CVSS 9.8 and a CVSS 10.0 in this collection typically differ on that single metric, not on exploitability.

The scoring and the vector trace to NVD alone in our provenance data. No second ingested source corroborates or contradicts them.

Evidence and confidence

  • Medium confidence — every substantive claim here. The CVSS score, the vector, the CWE-502 classification, and the affected-version ceiling of 4.16.7.1 all trace to NVD alone. The exploitation report traces to VulnCheck’s KEV feed alone. Nothing in our ingested data contradicts any of it; nothing corroborates it either.
  • Unknown — exploitation probability. No EPSS score has been ingested for this CVE.
  • Not established — remote code execution as an NVD-asserted outcome, and the specific fixed release. NVD names the affected ceiling, not the remediated version.

Our data carries no fixed-version field. Verify the remediated release against GiveWP’s own advisory or the Patchstack database entry NVD links, rather than assuming the next patch version after 4.16.7.1 is sufficient.

Why this matters

GiveWP processes donations, which means the sites running it are disproportionately nonprofits, and the plugin’s role puts it adjacent to payment flows and donor records. A site-level compromise of a fundraising platform is therefore a plausible route to personal and financial data belonging to people who never interacted with the vulnerable code themselves. That is an argument for treating this as higher priority than a generic plugin flaw, independent of the exploitation question.

The exploitation question still deserves a defender’s honest answer. A single-sourced exploitation report is not nothing — VulnCheck is a real catalog with real sourcing, not a rumour aggregator — but it is weaker evidence than a CISA listing, and it should drive a different response than one. The sensible posture is to patch on the severity and the unauthenticated reach, both of which are well established, rather than to wait for exploitation confirmation or to treat the VulnCheck entry as equivalent to a KEV mandate.

This CVE also sits inside a pattern our own ingested data makes visible: three WordPress plugin CVEs scored 10.0 appeared in VulnCheck’s KEV feed between August 18 and August 31, 2026, none of them CISA-listed. The other two are CVE-2026-82970 in WP Cookie Notice, which shares this CVE’s August 31 VulnCheck date, and CVE-2026-73343 in WP Compress. Different vendors, different weakness classes, identical CVSS vectors — the common factor is the plugin execution model, not a shared defect.

For the same weakness class outside the WordPress ecosystem, see our coverage of CVE-2026-86404 in Red Hat AMQ Artemis, where the deserialization surface is a message broker rather than a web plugin.

Frequently Asked Questions

What is CVE-2026-82222? A CVSS 10.0 deserialization-of-untrusted-data vulnerability (CWE-502) in the GiveWP WordPress donation plugin, affecting releases through 4.16.7.1, which NVD states allows object injection.

Is CVE-2026-82222 being actively exploited? VulnCheck’s KEV feed reports it as exploited, dated August 31, 2026. That is a single source. CISA has not added this CVE to its own Known Exploited Vulnerabilities catalog as of our September 16, 2026 ingestion, and we have no independent corroboration, so treat the exploitation status as reported rather than confirmed.

Does this CVE create a federal patching deadline? No. Binding Operational Directive 26-04 obligations follow CISA KEV listing, and this CVE is not CISA-listed. The severity case for patching stands on its own.

Which GiveWP version fixes it? NVD names releases through 4.16.7.1 as affected but does not state a fixed version, and our ingested data carries none. Confirm the remediated release against GiveWP’s advisory or the linked Patchstack entry.

Does object injection mean remote code execution here? NVD’s record asserts object injection, not code execution. The linked Patchstack advisories are titled in terms of object injection reaching remote code execution, which is suggestive but indirect. Plan for the more severe outcome; do not cite it as an NVD finding.

Why is this scored 10.0 when comparable flaws score 9.8? The difference is the CVSS scope metric. This vector sets scope to changed (S:C), reflecting that a compromised plugin affects the whole WordPress site rather than only the plugin, which pushes an otherwise-9.8 profile to the maximum.


Severity, vector, weakness classification, affected-version ceiling, and description sourced from the National Vulnerability Database record for CVE-2026-82222. Exploitation status and the August 31, 2026 catalog date are reported by VulnCheck KEV, an authenticated feed with no public per-CVE page to cite. This CVE is not listed in CISA’s Known Exploited Vulnerabilities catalog as reflected in our ingestion through September 16, 2026. Advisory references linked from NVD: Patchstack research and Patchstack database entry. Aggregated September 17, 2026. See more vulnerability intelligence.

Report an error

Found a factual error, an outdated figure, or a broken source link? Let us know and our editorial desk will review it.


Sources & evidence

01 National Vulnerability Database (NVD)
02 VulnCheck KEV

Related intelligence


Analyst tools