started · updated
GiveWP plugin faces critical vulnerability alongside malicious PHP package threats
Multiple cybersecurity threats have been identified targeting various software ecosystems. A critical vulnerability in the GiveWP plugin for WordPress, designated as CVE-2026-82222, has received a maximum CVSS score of 10.0. This flaw allows for remote command execution on vulnerable servers. With over 100,000 installations, administrators are urged to update to version 4.16.7.2 or later to mitigate the risk.
In a separate development, malicious actors are utilizing PHP packages on Packagist to deploy spyware. Specifically, 13 rogue themes have been identified that target unpatched iPhones to steal cryptocurrency wallet seeds. Additionally, flaws in the Composer dependency manager have been noted, potentially allowing malicious dependencies to expose sensitive files and SSH keys.
Entities
Composer · GiveWP · Patchstack · WordPress