News

GiveWP WordPress donation plugin flaw lets hackers execute server commands

  • Bill Toulas--BleepingComputer
  • published date: 2026-08-28 18:18:55 UTC

A maximum-severity vulnerability in the GiveWP plugin for WordPress allows an unauthenticated attacker to execute arbitrary commands on the hosting server. [...]

A maximum-severity vulnerability in the GiveWP plugin for WordPress allows an unauthenticated attacker to execute arbitrary commands on the hosting server. The security issue is identified as CVE-20… [+3112 chars]