ZeroHour
Patchstackpublished ()ingested Patchstack

Unauthenticated PHP Object Injection to Remote Code Execution on GiveWP

mediumVulnerabilityimportance 42
AI summary · glm-5.3-flash

Patchstack details an unauthenticated PHP object injection chain enabling remote code execution in the GiveWP WordPress donation plugin.

Patchstack disclosed an unauthenticated remote code execution vulnerability in the GiveWP WordPress donation plugin. An attacker with no account can execute arbitrary commands on the server of an affected GiveWP site. The full chain is reachable when a site has one published donation form and one active payment gateway, a configuration the researcher describes as a common default.

  • Unauthenticated attacker can achieve RCE
  • Affects the GiveWP WordPress donation plugin
  • Chain reachable under common default configurations
  • Disclosed via Patchstack vulnerability research
Full article

This blog post is about an unauthenticated remote code execution vulnerability in the GiveWP plugin. An attacker with no account can run arbitrary commands on the server of a GiveWP site that has one published donation form and one active payment gateway which, on the versions where the chain is fully reachable, describes a default […]

This source does not provide full text. Read it at patchstack.com.