Deserialization of Untrusted Data Vulnerability Affects GiveWP
CVE-2024-30229
8HIGH
Key Information:
- Vendor
- GiveWP
- Status
- GiveWP
- Vendor
- CVE Published:
- 28 March 2024
Summary
A deserialization of untrusted data vulnerability has been identified in GiveWP, a popular plugin for WordPress. This flaw can potentially allow attackers to execute arbitrary code by manipulating serialized PHP objects. The vulnerability affects all versions of GiveWP prior to and including 3.4.2. Users of the plugin are advised to update to the latest version to mitigate the risks associated with this exploit, as malicious actors can leverage this vulnerability to compromise website integrity and security.
Affected Version(s)
GiveWP <= 3.4.2
References
CVSS V3.1
Score:
8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Collectors
NVD DatabaseMitre Database
Credit
Rafie Muhammad (Patchstack)