< Back to situation

[REVISION HISTORY]

Security vulnerabilities in GiveWP and Composer software

Updated 1 time since CLSTR started tracking revisions of this situation.

What changed

2026-08-31 08:53 UTC → 2026-09-04 00:05 UTC · added removed

Security researchers have identified critical vulnerabilities in several widely used software tools, most notably the GiveWP WordPress plugin and the PHP dependency manager Composer. In the GiveWP plugin, a critical flaw designated CVE-2026-82222 was identified. This vulnerability involves unauthenticated PHP Object Injection that allows for Remote Code Execution (RCE), potentially granting attackers full server access without requiring user interaction. GiveWP released The flaw has received a maximum CVSS score of 10.0. With over 100,000 installations, administrators are urged to update to version 4.16.7.2 or later to address this issue. mitigate the risk. Additionally, Composer was found to have a vulnerability (CVE-2026-59944) involving path traversal and symbolic-link handling. This flaw could allow malicious packages to access sensitive system files, such as SSH keys, by changing file permissions. Fixes have been issued in Composer versions 2.10.3 and 2.2.30. In a related development involving the PHP ecosystem, malicious actors are utilizing packages on Packagist to deploy spyware. Specifically, 13 rogue themes have been identified that target unpatched iPhones to steal cryptocurrency wallet seeds.

Versions

  1. 2026-09-04 00:05 UTC Security vulnerabilities in GiveWP and Composer software
  2. 2026-08-31 08:53 UTC Security vulnerabilities in GiveWP and Composer software

Only revisions since CLSTR began indexing content versions appear here. Select a version to see what changed compared to the one before it.