GiveWP
cpe:2.3:a:givewp:give:*:*:*:*:wordpress:*:*, +1 more
- <= 3.19.2
A PHP Object Injection vulnerability has been identified in the GiveWP Donation Plugin and Fundraising Platform for WordPress, affecting all versions through 3.19.2. The vulnerability arises from the deserialization of untrusted input from the donation form, such as 'firstName', allowing unauthenticated attackers to inject PHP objects. The presence of a Property-Oriented Programming (POP) chain could enable attackers to delete arbitrary files on the server, potentially leading to remote code execution. While version 3.19.3 was released, it only partially addressed the issue, with a complete patch available in version 3.19.4.
Exploitation of this vulnerability allows for unauthenticated PHP Object Injection, with the potential for remote code execution due to the presence of a POP chain.
Users are advised to update to version 3.19.4 or later.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.