CVE-2024-37099

CRITICAL EXPLOITED

GiveWP < 3.14.1 - Unauthenticated PHP Object Injection via Deserialization

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2024-37099 has been observed exploited in the wild (reported by VulnCheck KEV).

Description

Deserialization of Untrusted Data vulnerability in Liquid Web GiveWP allows Object Injection.This issue affects GiveWP: from n/a through 3.14.1.

Scores

CVSS v3 10.0
EPSS 0.0056
EPSS Percentile 42.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

VulnCheck KEV 2024-08-09
CWE
CWE-502
Status published
Products (2)
givewp/givewp < 3.14.2
Liquid Web/GiveWP < 3.14.1
Published Aug 19, 2024
Tracked Since Feb 18, 2026