# Security vulnerabilities in GiveWP and Composer software

> Live situation record from CLSTR: https://clstr.news/situations/security-vulnerabilities-in-givewp-and-composer-software
> Updated: 2026-08-31T07:41:24.000Z. Sources: 7. Developments: 2.

Security researchers have identified critical vulnerabilities in several widely used software tools, most notably the GiveWP WordPress plugin and the PHP dependency manager Composer.

In the GiveWP plugin, a critical flaw designated CVE-2026-82222 was identified. This vulnerability involves unauthenticated PHP Object Injection that allows for Remote Code Execution (RCE), potentially granting attackers full server access without requiring user interaction. The flaw has received a maximum CVSS score of 10.0. With over 100,000 installations, administrators are urged to update to version 4.16.7.2 or later to mitigate the risk.

Additionally, Composer was found to have a vulnerability (CVE-2026-59944) involving path traversal and symbolic-link handling. This flaw could allow malicious packages to access sensitive system files, such as SSH keys, by changing file permissions. Fixes have been issued in Composer versions 2.10.3 and 2.2.30.

In a related development involving the PHP ecosystem, malicious actors are utilizing packages on Packagist to deploy spyware. Specifically, 13 rogue themes have been identified that target unpatched iPhones to steal cryptocurrency wallet seeds.

## Timeline

### 2026-08-31: GiveWP plugin faces critical vulnerability alongside malicious PHP package threats

Critical vulnerabilities have been identified in the GiveWP WordPress plugin, alongside malicious PHP packages on Packagist designed to steal iPhone crypto seeds and expose sensitive data via Composer.

5 sources. https://clstr.news/cluster/composer-and-givewp-software-face-critical-security-vulnerabilities

### 2026-08-27: GiveWP and rsync face critical security vulnerabilities

Critical security vulnerabilities have been identified in the GiveWP WordPress plugin and the rsync utility, affecting server integrity and network security.

2 sources. https://clstr.news/cluster/givewp-and-rsync-face-critical-security-vulnerabilities

---
Cite as: Security vulnerabilities in GiveWP and Composer software. CLSTR, https://clstr.news/situations/security-vulnerabilities-in-givewp-and-composer-software
