PT-2026-96645 · WordPress · Give Tributes

·

CVE-2026-19658

·

Published

2026-09-22

·

Updated

2026-09-23

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Give Tributes versions prior to 2.3.2
Description The Give Tributes plugin for WordPress is susceptible to PHP Object Injection through the deserialization of untrusted input. This allows unauthenticated attackers to inject a PHP Object. The issue is only reachable when the Allow Multiple Recipients option is enabled for the donation form and the eCard Custom Message option is disabled. While no POP chain (a sequence of gadgets used to execute arbitrary code during deserialization) is present within the plugin itself, the presence of a POP chain in another installed plugin or theme could allow an attacker to delete arbitrary files, retrieve sensitive data, or execute code.
Recommendations Update the plugin to a version newer than 2.3.1. Disable the Allow Multiple Recipients option for donation forms as a temporary mitigation measure.

Fix

Deserialization of Untrusted Data

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-19658

Affected Products

Give Tributes