GiveWP – Donation Plugin and Fundraising Platform <= 3.14.1 - Unauthenticated PHP Object Injection to Remote Code Execution

2024-08-19 13:55
villu164

Strategic Overview

Status
Patched in 3.14.2
Affected Version<= 3.14.1
CVSS10.0Critical
CVECVE-2024-5932
View all GiveWP – Donation Plugin and Fundraising Platform vulnerabilities

Vulnerability Overview

The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.14.1 via deserialization of untrusted input from the 'give_title' parameter. This makes it possible for unauthenticated attackers to inject a PHP Object. The additional presence of a POP chain allows attackers to execute code remotely, and to delete arbitrary files.

Technical Analysis

REMEDIATION: Update to version 3.14.2, or a newer patched version --- IDENTIFIER: CWE-502 (Deserialization of Untrusted Data) The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C