The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.19.2 via deserialization of untrusted input from the donation form like 'firstName'. This makes it possible for unauthenticated attackers to inject a PHP Object. The additional presence of a POP chain allows attackers to delete arbitrary files on the server that makes remote code execution possible. Please note this was only partially patched in 3.19.3, a fully sufficient patch was not released until 3.19.4. However, another CVE was assigned by another CNA for version 3.19.3 so we will leave this as affecting 3.19.2 and before. We have recommended the vendor use JSON encoding to prevent any further deserialization vulnerabilities from being present.
                
            Metrics
Affected Vendors & Products
References
        History
                    Tue, 25 Feb 2025 16:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| First Time appeared | Givewp Givewp givewp | |
| CPEs | cpe:2.3:a:givewp:givewp:*:*:*:*:*:wordpress:*:* | |
| Vendors & Products | Givewp Givewp givewp | 
Mon, 13 Jan 2025 18:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Metrics | ssvc 
 | 
Sat, 11 Jan 2025 07:30:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Description | The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.19.2 via deserialization of untrusted input from the donation form like 'firstName'. This makes it possible for unauthenticated attackers to inject a PHP Object. The additional presence of a POP chain allows attackers to delete arbitrary files on the server that makes remote code execution possible. Please note this was only partially patched in 3.19.3, a fully sufficient patch was not released until 3.19.4. However, another CVE was assigned by another CNA for version 3.19.3 so we will leave this as affecting 3.19.2 and before. We have recommended the vendor use JSON encoding to prevent any further deserialization vulnerabilities from being present. | |
| Title | GiveWP – Donation Plugin and Fundraising Platform <= 3.19.2 - Unauthenticated PHP Object Injection | |
| Weaknesses | CWE-502 | |
| References |  | |
| Metrics | cvssV3_1 
 | 
 MITRE
                        MITRE
                    Status: PUBLISHED
Assigner: Wordfence
Published: 2025-01-11T07:21:53.510Z
Updated: 2025-01-13T17:12:05.279Z
Reserved: 2024-12-20T21:49:42.876Z
Link: CVE-2024-12877
 Vulnrichment
                        Vulnrichment
                    Updated: 2025-01-13T17:11:57.792Z
 NVD
                        NVD
                    Status : Analyzed
Published: 2025-01-11T08:15:26.127
Modified: 2025-02-25T15:53:19.030
Link: CVE-2024-12877
 Redhat
                        Redhat
                    No data.