← Back to Feed
GiveWP WordPress donation plugin flaw lets hackers execute server commands
August 28, 2026 · BleepingComputer · Severity: HIGH
A maximum-severity vulnerability in the GiveWP plugin for WordPress allows an unauthenticated attacker to execute arbitrary commands on the hosting server.
Key Takeaways
- A maximum-severity unauthenticated remote code execution vulnerability exists in the GiveWP WordPress donation plugin.
- Attackers can exploit this flaw to execute arbitrary commands on the hosting server, potentially compromising the entire site.
- Site administrators must immediately update the GiveWP plugin to the latest patched version to prevent exploitation.