CVE-2026-82222
10
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Summary
Deserialization of Untrusted Data vulnerability in Liquid Web / StellarWP GiveWP allows Object Injection.
This issue affects GiveWP: from n/a through 4.16.7.1.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Liquid Web / StellarWP | GiveWP | n/a <= 4.16.7.1 | affected |
Weaknesses
- CWE-502: CWE-502 Deserialization of Untrusted Data
ADP Enrichment
CISA ADP Vulnrichment
- SSVC:
- Exploitation: none
- Automatable: yes
- Technical Impact: total
References
- https://patchstack.com/database/wordpress/plugin/give/vulnerability/wordpress-givewp-plugin-4-16-7-1-remote-code-execution-rce-vulnerability?_s_id=cve
- https://patchstack.com/articles/unauthenticated-php-object-injection-to-remote-code-execution-on-givewp?_s_id=cve
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.