Back to all news
Security

GiveWP WordPress donation plugin flaw lets hackers execute server commands

BleepingComputer·August 28, 2026·1 min read
GiveWP WordPress donation plugin flaw lets hackers execute server commands

A maximum-severity vulnerability in the GiveWP plugin for WordPress allows an unauthenticated attacker to execute arbitrary commands on the hosting server. The flaw, which has not yet been assigned a CVE, poses a critical risk to websites using the donation plugin. Users are advised to update to the latest version as soon as a patch is available.

Read at BleepingComputer
Daily crypto arcade

Read the news, then play it.

Chainshorts turns crypto headlines into a daily game. Catch up in 60 words, then jump into daily lucky draws for a shot at the pot.

Open ChainshortsGet it on the Solana dApp Store