CVE-2024-5932

Published Aug 20, 2024

Last updated 2 years ago

Overview

Description
The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.14.1 via deserialization of untrusted input from the 'give_title' parameter. This makes it possible for unauthenticated attackers to inject a PHP Object. The additional presence of a POP chain allows attackers to execute code remotely, and to delete arbitrary files.
Source
security@wordfence.com
NVD status
Analyzed
Products
givewp

Risk scores

CVSS 3.1

Type
Primary
Base score
9.8
Impact score
5.9
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity
CRITICAL

Weaknesses

nvd@nist.gov
CWE-502
security@wordfence.com
CWE-502

Social media

Hype score
Not currently trending
  1. TRC analysis shows attackers exploiting CVE-2024-5932 within days to bypass JFrog Artifactory authentication and mint admin tokens. They then enumerated users and systems to identify pathways into connected build pipelines. Runtime segmentation helps contain post-compromise

    @aviatrixtrc

    2 Sept 2026

    55 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. ¡Acabo de rootear Giveback en @hackthebox_eu! 🚩 🔸 CVE-2024-5932 (GiveWP) → RCE 🔸 CVE-2024-4577 (PHP-CGI) → pivote en K8s 🔸 CVE-2024-21626 (runc) → escape de contenedor → root https://t.co/mF7niWbmNt #HackTheBox #HTB #CVE #Kubernetes #Pentesting #

    @cyberknight_91

    12 May 2026

    7 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  3. HackTheBox - GiveBack 🧩 Plugin vulnerable de WordPress - CVE-2024-5932 🔁 CGI-PHP vulnerable - CVE-2024-4577 🔑 Kubernetes secrets + acceso SSH 🚀 Abuso de runc para escalar privilegios https://t.co/F8QTI2T9UZ

    @sckull_

    21 Feb 2026

    85 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  4. Everest Forms WordPress Plugin CVE-2025-1128 exploit domains lists WordPress GiveWP POP to RCE (CVE-2024-5932) list domains Ultimate Member Unauthorized Database Access / SQLi CVE-2024-1071

    @stem__shop

    3 Apr 2025

    49 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. 10万サイト以上が使用しているWordPressのプラグインGiveWPに重大(Critical)な脆弱性。CVE-2025-22777はCVSSスコア9.8で、認証不要のPHPオブジェクトインジェクション。データベース内の安全でないメタデータをデシリアライズできることに起因。CVE-2024-5932の修正不足。 https://t.co/3B6ehsbiEm

    @__kokumoto

    12 Jan 2025

    1534 Impressions

    2 Retweets

    12 Likes

    1 Bookmark

    1 Reply

    1 Quote

  6. CVE-2024-5932 這個是wordpress的一個叫做GiveWP Donation的插件 (用來捐錢的嗎?) 只簡單搜尋了有安裝v3.14.2版的機器 https://t.co/Le6Qflorv3

    @annpigpigpig

    12 Jan 2025

    42 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

Configurations