started · updated
GiveWP and rsync face critical security vulnerabilities
Multiple software vulnerabilities have been identified in widely used tools. A critical flaw, rated 10/10 in severity, was discovered in the GiveWP WordPress plugin, which is used by over 100,000 websites to manage online donations. The vulnerability, designated CVE-2026-82222, involves unauthenticated PHP Object Injection leading to Remote Code Execution (RCE). This allows attackers to bypass controls and gain full server access by using a POP Chain technique to execute commands through legitimate internal rules.
Separately, the rsync project has released version 3.5.0 to address 33 vulnerabilities discovered during a security audit and fuzzing campaign. These include one critical vulnerability (CVE-2026-53791) related to the “proxy protocol = true” parameter, which previously allowed clients to spoof source addresses. The update also fixes 17 high-risk and 15 medium-risk issues involving race conditions, path traversal, and denial of service attacks.