PoC Index

CVE-2024-5932

CRITICAL 10.0EPSS 74.3%

The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.14.1 via deserialization of untrusted input from the 'give_title' parameter. This makes it possible for unauthenticated attackers to inject a PHP Object. The additional presence of a POP chain allows attackers to execute code remotely, and to delete arbitrary files.

CVSS v3.1
9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v3.1
10.0 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
EPSS
74.28% chance of exploitation in the next 30 days, 99th percentile
Nuclei
critical · CWE-502
Published
2024-08-20
Updated
2026-04-08

Proof-of-concept exploits (9)

Nuclei templates (1)

Metasploit modules (1)

References

Related