GiveWP – Donation Plugin and Fundraising Platform <= 3.16.3 - Unauthenticated PHP Object Injection to Remote Code Execution

2024-10-15 00:00
lefab

Strategic Overview

Status
Patched in 3.16.4
Affected Version<= 3.16.3
CVSS9.8Critical
CVECVE-2024-9634
View all GiveWP – Donation Plugin and Fundraising Platform vulnerabilities

Vulnerability Overview

The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.16.3 via deserialization of untrusted input from the give_company_name parameter. This makes it possible for unauthenticated attackers to inject a PHP Object. The additional presence of a POP chain allows attackers to achieve remote code execution.

Technical Analysis

REMEDIATION: Update to version 3.16.4, or a newer patched version --- IDENTIFIER: CWE-502 (Deserialization of Untrusted Data) The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C