← Back to Feed

GiveWP WordPress donation plugin flaw lets hackers execute server commands

August 28, 2026 · BleepingComputer · Severity: HIGH

A maximum-severity vulnerability in the GiveWP plugin for WordPress allows an unauthenticated attacker to execute arbitrary commands on the hosting server.

Key Takeaways

  • A maximum-severity unauthenticated remote code execution vulnerability exists in the GiveWP WordPress donation plugin.
  • Attackers can exploit this flaw to execute arbitrary commands on the hosting server, potentially compromising the entire site.
  • Site administrators must immediately update the GiveWP plugin to the latest patched version to prevent exploitation.
☕ Buy a Coffee