← back
CVE-2024-30229highobserved exploitationCWE-502

WordPress Give plugin <= 3.4.2 - PHP Object Injection vulnerability

43Vexday Risk Score

Prioritize patching. It exploitation observed by VulnCheck.

ssvc Actcvss 8epss 0.6%
from disclosure to weapon
Published on NVDMar 28
VulnCheckMar 26
exploitation probability
0.6%top 54% of all CVEs
observed exploitation
yesVulnCheck
In short

The WordPress Give plugin has a flaw that allows attackers to inject malicious code by sending specially crafted data. An attacker can exploit this to take control of the website or steal sensitive information.

Technical detail

A PHP object injection vulnerability in GiveWP <= 3.4.2 stems from unsafe deserialization of untrusted user-supplied data. An attacker can craft malicious serialized objects to execute arbitrary code with the privileges of the web server, potentially leading to remote code execution or data exfiltration.

Summary generated and translated by AI from the official description.
Deserialization of Untrusted Data vulnerability in StellarWP GiveWP give.This issue affects GiveWP: from n/a through <= 3.4.2.
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H
Affected products
StellarWP · GiveWP