SEPTEMBER 15, 2026
Live Feed
Back to database
Case File

CVE-2026-82222

CRITICAL · CVSS 10 EPSS 1.55%

Source: NVD + CISA KEV + EPSS · Published 2026-08-28 · Last synced 2026-09-15

CyberRota Analysis

AI-Generated

A critical deserialization vulnerability in GiveWP versions up to 4.16.7.1 allows for object injection, potentially enabling attackers to execute arbitrary code or manipulate application behavior. Organizations using affected versions of GiveWP should prioritize immediate remediation to mitigate the risk of exploitation, given the severity of the vulnerability. This is particularly crucial for those handling sensitive data or financial transactions through the platform.

CVE
CVE-2026-82222
Severity
CRITICAL
CVSS
10
EPSS
1.55%

Original NVD Description

Deserialization of Untrusted Data vulnerability in Liquid Web / StellarWP GiveWP allows Object Injection. This issue affects GiveWP: from n/a through 4.16.7.1.