Deserialization of Untrusted Data Vulnerability Affects GiveWP
CVE-2024-30229

8HIGH

Key Information:

Vendor
GiveWP
Status
GiveWP
Vendor
CVE Published:
28 March 2024

Summary

A deserialization of untrusted data vulnerability has been identified in GiveWP, a popular plugin for WordPress. This flaw can potentially allow attackers to execute arbitrary code by manipulating serialized PHP objects. The vulnerability affects all versions of GiveWP prior to and including 3.4.2. Users of the plugin are advised to update to the latest version to mitigate the risks associated with this exploit, as malicious actors can leverage this vulnerability to compromise website integrity and security.

Affected Version(s)

GiveWP <= 3.4.2

References

CVSS V3.1

Score:
8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Collectors

NVD DatabaseMitre Database

Credit

Rafie Muhammad (Patchstack)
.