Monitor this situation.
Unsubscribe anytime.
[SITUATION] · [QUIET] · [TECHNOLOGY]
2 clusters · 7 sources · 4 days · First seen · Last updated
Security vulnerabilities in GiveWP and Composer software
Overview
Security researchers have identified critical vulnerabilities in several widely used software tools, most notably the GiveWP WordPress plugin and the PHP dependency manager Composer.
In the GiveWP plugin, a critical flaw designated CVE-2026-82222 was identified. This vulnerability involves unauthenticated PHP Object Injection that allows for Remote Code Execution (RCE), potentially granting attackers full server access without requiring user interaction. The flaw has received a maximum CVSS score of 10.0. With over 100,000 installations, administrators are urged to update to version 4.16.7.2 or later to mitigate the risk.
Additionally, Composer was found to have a vulnerability (CVE-2026-59944) involving path traversal and symbolic-link handling. This flaw could allow malicious packages to access sensitive system files, such as SSH keys, by changing file permissions. Fixes have been issued in Composer versions 2.10.3 and 2.2.30.
In a related development involving the PHP ecosystem, malicious actors are utilizing packages on Packagist to deploy spyware. Specifically, 13 rogue themes have been identified that target unpatched iPhones to steal cryptocurrency wallet seeds.
Entities
WordPress · GiveWP · rsync · Patchstack · Composer
Timeline
-
12 days ago
[TECHNOLOGY] 5 sourcesGiveWP plugin faces critical vulnerability alongside malicious PHP package threatsCritical vulnerabilities have been identified in the GiveWP WordPress plugin, alongside malicious PHP packages on Packagist designed to steal iPhone crypto seeds and expose sensitive data via Composer.
-
15 days ago
[TECHNOLOGY] 2 sourcesGiveWP and rsync face critical security vulnerabilitiesCritical security vulnerabilities have been identified in the GiveWP WordPress plugin and the rsync utility, affecting server integrity and network security.
Sources
bitmag.com.br · cybernoz.com · invitehealth.substack.com · planningassociates.com.au · securityaffairs.co · spotlight.lu · tecnoandroid.it
This summary has been updated 1 time: see revision history