CVE-2025-0912
CRITICALGivewp < 3.20.0 - Insecure Deserialization
Title source: ruleDescription
The Donations Widget plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.19.4 via deserialization of untrusted input from the Donation Form through the 'card_address' parameter. This makes it possible for unauthenticated attackers to inject a PHP Object. The additional presence of a POP chain allows attackers to achieve remote code execution.
References (6)
Scores
CVSS v3
9.8
EPSS
0.0368
EPSS Percentile
87.8%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Classification
CWE
CWE-502
Status
published
Affected Products (1)
givewp/givewp
< 3.20.0
Timeline
Published
Mar 04, 2025
Tracked Since
Feb 18, 2026