Tech News
GiveWP Plugin Vulnerability Risked 100,000+ Websites To RCE
A critical code execution vulnerability has been discovered in the GiveWP WordPress plugin, putting thousands of websites at risk. It is essential for users of this plugin to update to the latest release in order to patch this security issue.
GiveWP Plugin Vulnerability Exposed to Remote Code Execution
Recently, Wordfence revealed a serious code execution vulnerability in the GiveWP plugin. GiveWP is a popular WordPress plugin that offers features for easy donations and fundraising. However, with over 100,000 active installations, the plugin poses a significant security risk to numerous WordPress sites worldwide due to this vulnerability.
The vulnerability, identified as a PHP Object Injection flaw, affected all versions of the GiveWP plugin up to v.3.14.1. It stemmed from the “deserialization of untrusted input from the ‘give_title’ parameter.” Exploiting this flaw allowed unauthorized attackers to inject a malicious PHP object. Furthermore, the presence of the POP chain enabled attackers to carry out various malicious activities, including remote code execution and deletion of files.
Assigned the CVE-2024-5932 identifier, this vulnerability was rated critical with a CVSS score of 10.0. A score of 10.0 signifies the highest level of severity for a vulnerability, indicating a significant threat to affected users if exploited.
Patch Released – Act Now!
The security researcher Villu Orav (villu164) first identified this vulnerability and responsibly disclosed it through Wordfence’s bug bounty program.
In response to the report, the GiveWP team promptly addressed the issue in plugin version 3.14.2, which was released earlier this month. Wordfence rewarded the researcher with a $4998 bug bounty for the discovery.
The latest version of the plugin listed on the official WordPress page is 3.15.1. Users are strongly advised to update their websites to this version to ensure they receive all security patches and enhancements.
We welcome your feedback in the comments section.
-
Tech News3 months ago
Bangladeshi police agents accused of selling citizens’ personal information on Telegram
-
Motivation3 months ago
The Top 20 Motivational Instagram Accounts to Follow (2024)
-
Self Development4 months ago
Don’t Waste Your Time in Anger, Regrets, Worries and Grudges
-
Destination4 months ago
Our new fixed tours are your ultimate Aussie & Kiwi adventure!
-
Activities4 months ago
Family Holiday Checklist | What To Pack Family Holiday
-
Breaking News4 months ago
Democrats and allies to flood airwaves, drop more than $125M on abortion push
-
Destination3 months ago
Turkish Airlines carries 7.2 mn passengers in May, launches new sustainability brand, BA
-
Gaming3 months ago
Concord price, beta, preorder details for PS5 and PC confirmed