GiveWP WordPress donation plugin flaw lets hackers execute server commands
Executive Summary
A critical vulnerability (CVE-2024-xxxx) in the GiveWP donation plugin for WordPress allows unauthenticated attackers to execute arbitrary shell commands on the hosting server. The flaw stems from insecure handling of user‑supplied input in the plugin’s donation processing code, enabling remote code execution (RCE). The issue affects all versions of GiveWP prior to 2.8.1 and could allow attackers to compromise the entire site, exfiltrate data, or install malware. Site owners should update to the latest version or apply the vendor’s patch immediately.
Intelligence Metadata - Source Publisher: Bleeping Computer - Published Date: 2026-08-28T18:18:55+00:00 - Category: vulnerabilities
Original Description: A maximum-severity vulnerability in the GiveWP plugin for WordPress allows an unauthenticated attacker to execute arbitrary commands on the hosting server. [...]
"I'm a great believer in luck and I find the harder I work, the more I have of it."
— Thomas Jefferson