CVE-2024-8353
Last modified
CVE-2024-8353 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.16.1 via deserialization of untrusted input via several parameters like 'give_title' and 'card_address'. This makes it possible for unauthenticated attackers to inject a PHP Object. EPSS estimates a 29.10% chance of exploitation in the next 30 days.
Description
The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.16.1 via deserialization of untrusted input via several parameters like 'give_title' and 'card_address'. This makes it possible for unauthenticated attackers to inject a PHP Object. The additional presence of a POP chain allows attackers to delete arbitrary files and achieve remote code execution. This is essentially the same vulnerability as CVE-2024-5932, however, it was discovered the the presence of stripslashes_deep on user_info allows the is_serialized check to be bypassed. This issue was mostly patched in 3.16.1, but further hardening was added in 3.16.2.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Givewp | Givewp | < 3.16.2 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2024-8353?
How severe is CVE-2024-8353?
How do I fix CVE-2024-8353?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-8347A vulnerability classified as critical was found in SourceCo…9.8
- CVE-2024-8348A vulnerability, which was classified as critical, has been …9.8
- CVE-2024-8349The Uncanny Groups for LearnDash plugin for WordPress is vul…7.2
- CVE-2024-8350The Uncanny Groups for LearnDash plugin for WordPress is vul…2.7
- CVE-2024-8351Rejected reason: This CVE ID has been rejected or withdrawn …
- CVE-2024-8352The Social Web Suite – Social Media Auto Post, Social Media …7.5
- CVE-2024-8354A flaw was found in QEMU. An assertion failure was present i…5.5
- CVE-2024-8355Visteon Infotainment System DeviceManager iAP Serial Number …6.8
- CVE-2024-8356Visteon Infotainment VIP MCU Code Insufficient Validation of…7.8
- CVE-2024-8357Visteon Infotainment App SoC Missing Immutable Root of Trust…7.8
- CVE-2024-8358Visteon Infotainment UPDATES_ExtractFile Command Injection R…6.8
- CVE-2024-8359Visteon Infotainment REFLASH_DDU_FindFile Command Injection …6.8
Are you affected by CVE-2024-8353?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
