PT-2024-39731 · WordPress · Givewp

Fabrice Perez

+1

·

Published

2024-10-15

·

Updated

2025-02-27

·

CVE-2024-9634

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions GiveWP – Donation Plugin and Fundraising Platform versions up to, and including, 3.16.3
Description The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.16.3 via deserialization of untrusted input from the give company name parameter. This makes it possible for unauthenticated attackers to inject a PHP Object. The additional presence of a POP chain allows attackers to achieve remote code execution. Over 100,000 WordPress sites are potentially at risk.
Recommendations For versions up to, and including, 3.16.3, update to version 3.16.4 or later to prevent arbitrary code execution. As a temporary workaround, consider restricting access to the give company name parameter to minimize the risk of exploitation.

Fix

RCE

Deserialization of Untrusted Data

Weakness Enumeration

Related Identifiers

CVE-2024-9634

Affected Products

Givewp