PT-2026-96645 · WordPress · Give Tributes
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Give Tributes versions prior to 2.3.2
Description
The Give Tributes plugin for WordPress is susceptible to PHP Object Injection through the deserialization of untrusted input. This allows unauthenticated attackers to inject a PHP Object. The issue is only reachable when the Allow Multiple Recipients option is enabled for the donation form and the eCard Custom Message option is disabled. While no POP chain (a sequence of gadgets used to execute arbitrary code during deserialization) is present within the plugin itself, the presence of a POP chain in another installed plugin or theme could allow an attacker to delete arbitrary files, retrieve sensitive data, or execute code.
Recommendations
Update the plugin to a version newer than 2.3.1.
Disable the Allow Multiple Recipients option for donation forms as a temporary mitigation measure.
Fix
Deserialization of Untrusted Data
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Give Tributes