Junglewise Threat Intelligence

CVE-2026-82222: StellarWP GiveWP PHP object injection to RCE

CVE-2026-82222 · Severity: critical · CVSS 10 · Published 2026-08-28

Technologies: StellarWP GiveWP. Vendors: StellarWP.

Executive brief

GiveWP is a popular WordPress plugin for managing online donations and fundraising campaigns. A critical vulnerability in versions 4.16.7.1 and below allows unauthenticated attackers to execute arbitrary PHP code on the server through a chain of flaws in data deserialization. This could lead to complete server compromise, data theft, and malware installation with no prior warning or detection required.

Technical details

The vulnerability combines three weaknesses: (1) an unsafe "safe" unserialize helper in src/Helpers/Utils.php that uses allowed_classes=false, which does not neutralize untrusted objects but merely converts them to __PHP_Incomplete_Class placeholders that retain the original class name and properties; (2) a donation processing flow that accepts and deserializes user-controlled data from user meta fields (last_name) without proper sanitization; and (3) gadget chains in GiveWP's codebase that can be exploited upon deserialization. The attack is unauthenticated on default installations (versions 4.16.5.1 and below require only a published donation form and active payment gateway). Exploitation triggers remote code execution via the chained gadget chain when session data is unserialized on subsequent requests.

Affected products

  • StellarWP GiveWP through 4.16.7.1

Timeline

  • 2026-08-28: disclosed
  • 2026-08-28: advisory

References

Related threats