Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 27 Feb 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Givewp
Givewp givewp |
|
| CPEs | cpe:2.3:a:givewp:givewp:*:*:*:*:*:wordpress:*:* | |
| Vendors & Products |
Givewp
Givewp givewp |
Wed, 16 Oct 2024 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Webdevmattcrom
Webdevmattcrom givewp Donation Plugin And Fundraising Platform |
|
| CPEs | cpe:2.3:a:webdevmattcrom:givewp_donation_plugin_and_fundraising_platform:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Webdevmattcrom
Webdevmattcrom givewp Donation Plugin And Fundraising Platform |
|
| Metrics |
ssvc
|
Wed, 16 Oct 2024 02:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.16.3 via deserialization of untrusted input from the give_company_name parameter. This makes it possible for unauthenticated attackers to inject a PHP Object. The additional presence of a POP chain allows attackers to achieve remote code execution. | |
| Title | GiveWP – Donation Plugin and Fundraising Platform <= 3.16.3 - Unauthenticated PHP Object Injection to Remote Code Execution | |
| Weaknesses | CWE-502 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-04-08T17:17:52.783Z
Reserved: 2024-10-08T15:59:21.224Z
Link: CVE-2024-9634
Updated: 2024-10-16T16:36:50.059Z
Status : Analyzed
Published: 2024-10-16T02:15:07.487
Modified: 2025-02-27T18:47:11.020
Link: CVE-2024-9634
No data.
OpenCVE Enrichment
No data.