CVE-2024-5932
GiveWP – Donation Plugin and Fundraising Platform <= 3.14.1 - Unauthenticated PHP Object Injection to Remote Code Execution
- Published
- Aug 20, 2024
- Updated
- Apr 8, 2026
- Assigning CNA
- Wordfence
- Evidence observed
- Aug 6, 2026
Primary CVSS
nvd · CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:HHigh · next 30 days
- Percentile
- 99.5%
- Model date
- Sep 21, 2026
EPSS is a statistical estimate, not a certainty or a measure of impact. Combine it with CVSS, KEV status, exposure and your environment.
Summary
The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.14.1 via deserialization of untrusted input from the 'give_title' parameter. This makes it possible for unauthenticated attackers to inject a PHP Object. The additional presence of a POP chain allows attackers to execute code remotely, and to delete arbitrary files.
Sources
4- CVE-2024-5932Exploit
GiveWP PHP Object Injection exploit
Proof-of-concept exploit for CVE-2024-5932, a PHP object injection vulnerability in the GiveWP WordPress plugin, enabling unauthenticated remote code execution and arbitrary file deletion via a POP chain.
PoC for CVE-2024-5932.
- CVE-2024-5932-web-uiExploit
Python-based exploit for CVE-2024-5932 targeting a web UI vulnerability. Provides a simple script to demonstrate and test the security flaw.
Responsible use
Use vulnerability information only on systems you own or are authorized to test. Kitploit links to public research metadata and does not store exploit code or malicious payloads.