GiveWP chains three bugs to open unauthenticated command execution on WordPress
On 27 August 2026, GiveWP fixed CVE-2026-82222, a three-bug chain that turns a WordPress donation form into remote command execution with no real authentication. Administrators must upgrade to 4.16.7.2 and check for rogue accounts, even on sites where registration was disabled.