← back
CVE-2025-22777criticalCWE-502

WordPress GiveWP Plugin <= 3.19.3 - PHP Object Injection vulnerability

28Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 9.8epss 0.9%
exploitation probability
0.9%top 43% of all CVEs
observed exploitation
nono source reports it
In short

The GiveWP WordPress plugin has a flaw that allows attackers to inject malicious code by sending specially crafted data. If exploited, an attacker could take control of the website or steal sensitive information.

Technical detail

A PHP object deserialization vulnerability (CWE-502) in GiveWP <= 3.19.3 permits unauthenticated object injection through untrusted serialized data. An attacker can craft malicious serialized objects to trigger arbitrary code execution or access sensitive functionality without requiring authentication or user interaction.

Summary generated and translated by AI from the official description.
Deserialization of Untrusted Data vulnerability in StellarWP GiveWP give allows Object Injection.This issue affects GiveWP: from n/a through <= 3.19.3.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
StellarWP · GiveWP