GiveWP – Donation Plugin and Fundraising Platform <= 3.16.3 - Unauthenticated PHP Object Injection to Remote Code Execution
2024-10-15 00:00
lefabStrategic Overview
StatusPatched in 3.16.4
Affected PluginGiveWP – Donation Plugin and Fundraising Platform
Affected Version
<= 3.16.3CVSS9.8Critical
CVE
CVE-2024-9634Vulnerability Overview
The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.16.3 via deserialization of untrusted input from the give_company_name parameter. This makes it possible for unauthenticated attackers to inject a PHP Object. The additional presence of a POP chain allows attackers to achieve remote code execution.
Technical Analysis
REMEDIATION: Update to version 3.16.4, or a newer patched version --- IDENTIFIER: CWE-502 (Deserialization of Untrusted Data) The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C