Vulnerability record · CVE-2024-5932 · published 20 August 2024
CVE-2024-5932: GiveWP WordPress plugin PHP object injection enables remote code execution
Givewp · Givewp
GiveWP, a WordPress donation and fundraising plugin, deserializes untrusted input from the 'give_title' parameter in all versions up to and including 3.14.1, allowing PHP object injection. A POP chain present in the plugin lets an unauthenticated attacker turn that injection into remote code execution and arbitrary file deletion.
Description
The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.14.1 via deserialization of untrusted input from the 'give_title' parameter. This makes it possible for unauthenticated attackers to inject a PHP Object. The additional presence of a POP chain allows attackers to execute code remotely, and to delete arbitrary files.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityUnauthenticated network-reachable remote code execution with a CVSS of 9.8 and very high EPSS probability makes this an urgent patch.
What it is
GiveWP, a WordPress donation and fundraising plugin, deserializes untrusted input from the 'give_title' parameter in all versions up to and including 3.14.1, allowing PHP object injection. A POP chain present in the plugin lets an unauthenticated attacker turn that injection into remote code execution and arbitrary file deletion.
Impact
An attacker can execute arbitrary code on the WordPress host and delete arbitrary files, leading to full site compromise and potential server takeover.
Attack surface
Reachable over the network through the plugin's donation handling without authentication or user interaction, per the CVSS vector AV:N/AC:L/PR:N/UI:N. The 'give_title' parameter is the injection point.
Exploitation
Not listed in CISA KEV, but EPSS is 0.76803 (99.5th percentile), indicating high predicted exploitation activity; references are patch and third-party advisory links only, with no public exploit tag.
What to do
- Update GiveWP to a version later than 3.14.1 immediately.
- If patching is not possible, disable or remove the GiveWP plugin until it can be updated.
- Add WAF rules to block requests carrying serialized object payloads in the 'give_title' parameter.
- Restrict write access and monitor file integrity on the WordPress installation to catch post-exploitation file deletion or webshell drops.
- Review WordPress accounts and server logs for signs of compromise after any exposure window.
Detection
- Search web server logs for requests with serialized PHP object strings (e.g., 'O:' patterns) in the 'give_title' parameter.
- Monitor for unexpected file deletions or new PHP files in the WordPress plugin and upload directories.
- Alert on outbound network connections or process execution spawned by the web server user.
- Correlate GiveWP donation endpoint traffic with anomalous POST bodies during the exposure window.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2024-5932 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2024-5932), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.