漏洞描述
The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.14.1 via deserialization of untrusted input from the 'give_title' parameter.
影响产品
修复建议
建议关注厂商安全公告,及时升级至已修复版本,并结合实际资产暴露情况采取缓解措施。
参考链接
plugins.trac.wordpress.orghttps://plugins.trac.wordpress.org/browser/give/tags/3.12.0/includes/login-register.php#L235↗plugins.trac.wordpress.orghttps://plugins.trac.wordpress.org/browser/give/tags/3.12.0/includes/process-donation.php#L420↗plugins.trac.wordpress.orghttps://plugins.trac.wordpress.org/browser/give/tags/3.12.0/src/DonorDashboards/Tabs/EditProfileTab/AvatarRoute.php#L51↗plugins.trac.wordpress.orghttps://plugins.trac.wordpress.org/browser/give/tags/3.12.0/vendor/tecnickcom/tcpdf/tcpdf.php#L7861↗plugins.trac.wordpress.orghttps://plugins.trac.wordpress.org/browser/give/tags/3.12.0/vendor/vendor-prefixed/fakerphp/faker/src/Faker/ValidGenerator.php#L80↗www.rcesecurity.comhttps://www.rcesecurity.com/2024/08/wordpress-givewp-pop-to-rce-cve-2024-5932/↗thehackernews.comhttps://thehackernews.com/2024/08/givewp-wordpress-plugin-vulnerability.html↗