What the vulnerability does
01Description
Deserialization of Untrusted Data vulnerability in GiveWP GiveWP – Donation Plugin and Fundraising Platform.This issue affects GiveWP – Donation Plugin and Fundraising Platform: from n/a through 2.25.3.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
What the vulnerability does
Deserialization of Untrusted Data vulnerability in GiveWP GiveWP – Donation Plugin and Fundraising Platform.This issue affects GiveWP – Donation Plugin and Fundraising Platform: from n/a through 2.25.3.
Explanation of Vulnerability in Simple Terms
GiveWP versions up to 2.25.3 contain a deserialization vulnerability that allows attackers to execute arbitrary code on the site. An attacker can craft a malicious serialized object that, when processed by the plugin, runs their own PHP code with full site privileges. The attack requires user interaction—typically a victim clicking a malicious link or visiting an attacker-controlled page.
What an attacker can do
Run their own PHP code on the site with full administrative privileges.
Potential impact on your site
Complete compromise of the site, including access to all donation data, user accounts, and the ability to modify or delete content.
Conditions required to exploit
No authentication required, but the victim must click a link or visit a page controlled by the attacker.
Key dates
External resources
Related vulnerabilities