GiveWP – Donation Plugin and Fundraising Platform <= 3.14.1 - Unauthenticated PHP Object Injection to Remote Code Execution
2024-08-19 13:55
villu164Strategic Overview
StatusPatched in 3.14.2
Affected PluginGiveWP – Donation Plugin and Fundraising Platform
Affected Version
<= 3.14.1CVSS10.0Critical
CVE
CVE-2024-5932Vulnerability Overview
The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.14.1 via deserialization of untrusted input from the 'give_title' parameter. This makes it possible for unauthenticated attackers to inject a PHP Object. The additional presence of a POP chain allows attackers to execute code remotely, and to delete arbitrary files.
Technical Analysis
REMEDIATION: Update to version 3.14.2, or a newer patched version --- IDENTIFIER: CWE-502 (Deserialization of Untrusted Data) The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C