HomeSecurityVulnerability in GiveWP plugin puts thousands of sites at risk

Vulnerability in GiveWP plugin puts thousands of sites at risk

A serious vulnerability affects the WordPress donation plugin GiveWP and exposes more than 100,000 websites to remote code execution attacks.

GiveWP WordPress plugin vulnerability

The vulnerability is tracked as CVE-2024-5932 (CVSS score: 10.0) and affects all versions of the plugin before 3.14.2, which was released on August 7, 2024. A researcher, using the alias villu164, discovered and reported the security issue.

See also: Modern Events Calendar – WordPress: Hackers target vulnerability

The WordPress plugin GiveWP is “ vulnerable to PHP Object Injection in all versions up to 3.14.1, via deserialization of untrusted input from the “give_title” parameter ,” Wordfence said in a statement about the vulnerability. Wordfence explained that the vulnerability allows unauthorized attackers to inject a PHP Object. “ The additional presence of a POP chain allows attackers to execute code remotely and delete files .”

Attackers could execute malicious code on the server, making it imperative to immediately update the WordPress plugin, GiveWP.

See also: New Caesar Cipher Skimmer Targets WordPress, Magento, and OpenCart Sites

Importance of WordPress protection

Protecting WordPress websites is especially important for many reasons. First, WordPress websites are very popular, which means they are a prime target for cybercriminals. If your website is not protected, significant damage can occur.

See also: WordPress plugins at risk – Hackers create fake administrator accounts

Vulnerability in GiveWP plugin puts thousands of sites at risk
Vulnerability in GiveWP plugin puts thousands of sites at risk

Additionally, an unsecured WordPress site can undermine the trust and credibility you’ve built with customers your. If their data is compromised, they’re more likely to sue you and switch to other companies.

Securing your website is also important for maintaining the consistency and credibility of content your. If a hacker breaks into your WordPress site and corrupts the content, it can give the impression that you don't care enough about your website.

In other words, ensuring your WordPress website is secure isn’t just about protecting your data – it’s about maintaining your customers  ’ trust , preserving your company’s reputation, and staying on top of the competition.

Source: thehackernews.com

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS